ExamGecko
Question list
Search
Search

Question 254 - CISM discussion

Report
Export

Which of the following would MOST effectively ensure that a new server is appropriately secured?

A.
Performing secure code reviews
Answers
A.
Performing secure code reviews
B.
Enforcing technical security standards
Answers
B.
Enforcing technical security standards
C.
Conducting penetration testing
Answers
C.
Conducting penetration testing
D.
Initiating security scanning
Answers
D.
Initiating security scanning
Suggested answer: B

Explanation:

Enforcing technical security standards is the most effective way to ensure that a new server is appropriately secured because it ensures that the server complies with the organization's security policies and best practices, such as encryption, authentication, patching, and hardening. Performing secure code reviews is not relevant for securing a new server, unless it is running custom applications that need to be verified for security flaws. Conducting penetration testing is not sufficient for securing a new server, because it only identifies vulnerabilities that can be exploited by attackers, but does not fix them. Initiating security scanning is not sufficient for securing a new server, because it only detects known vulnerabilities or misconfigurations, but does not enforce security standards or remediate issues.

Reference: https://www.isaca.org/resources/isaca-journal/issues/2016/volume-4/technical-security-standards-for-information-systems https://www.isaca.org/resources/isaca-journal/issues/2017/volume-3/secure-code-review https://www.isaca.org/resources/isaca-journal/issues/2017/volume-2/the-value-of-penetration-testing https://www.isaca.org/resources/isaca-journal/issues/2016/volume-5/security-scanning-versus-penetration-testing

asked 01/10/2024
Matthew McConnell
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first