List of questions
Related questions
Question 1080 - CISSP discussion
A Certified Information Systems Security Professional (CISSP) with identity and access management (IAM) responsibilities is asked by the Chief Information Security Officer (CISO) to4 perform a vulnerability assessment on a web application to pass a Payment Card Industry (PCI) audit. The CISSP has never performed this before. According to the (ISC)? Code of Professional Ethics, which of the following should the CISSP do?
A.
Review the CISSP guidelines for performing a vulnerability assessment before proceeding to complete it
B.
Review the PCI requirements before performing the vulnerability assessment
C.
Inform the CISO that they are unable to perform the task because they should render only those services for which they are fully competent and qualified
D.
Since they are CISSP certified, they have enough knowledge to assist with the request, but will need assistance in order to complete it in a timely manner
Your answer:
0 comments
Sorted by
Leave a comment first