ExamGecko
Question list
Search
Search

Related questions

Question 1133 - CISA discussion

Report
Export

An IS auditor reviewing the database controls for a new e-commerce system discovers a security weakness in the database configuration. Which of the following should be the IS auditor's NEXT course of action?

A.
Identify existing mitigating controls.
Answers
A.
Identify existing mitigating controls.
B.
Disclose the findings to senior management.
Answers
B.
Disclose the findings to senior management.
C.
Assist in drafting corrective actions.
Answers
C.
Assist in drafting corrective actions.
D.
Attempt to exploit the weakness.
Answers
D.
Attempt to exploit the weakness.
Suggested answer: A

Explanation:

When an IS auditor discovers a security weakness in the database configuration, the next course of action should be to identify existing mitigating controls. This involves assessing whether any controls are already in place to address the weakness and mitigate the risk.Understanding the current state of controls helps the auditor determine the severity of the issue and whether additional corrective actions are necessary1.Reference:1(https://www.isaca.org/resources/insights-and-expertise/audit-programs-and-tools)

asked 18/09/2024
Angela Stevens
59 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first