ExamGecko
Question list
Search
Search

Question 302 - CISM discussion

Report
Export

What is the PRIMARY objective of performing a vulnerability assessment following a business system update?

A.
Determine operational losses.
Answers
A.
Determine operational losses.
B.
Improve the change control process.
Answers
B.
Improve the change control process.
C.
Update the threat landscape.
Answers
C.
Update the threat landscape.
D.
Review the effectiveness of controls
Answers
D.
Review the effectiveness of controls
Suggested answer: D

Explanation:

The primary objective of performing a vulnerability assessment following a business system update is to review the effectiveness of controls. A vulnerability assessment is a systematic review of security weaknesses in an information system. It evaluates if the system is susceptible to any known vulnerabilities, assigns severity levels to those vulnerabilities, and recommends remediation or mitigation, if and whenever needed1. A business system update is a process of modifying or enhancing an information system to improve its functionality, performance, security, or compatibility. A business system update may introduce new features, fix bugs, patch vulnerabilities, or comply with new standards or regulations2. Performing a vulnerability assessment following a business system update is important because it helps to:

* Review the effectiveness of controls that are implemented to protect the information sys-tem from threats and risks

* Identify any new or residual vulnerabilities that may have been introduced or exposed by the update

* Evaluate the impact and likelihood of potential incidents that may exploit the vulnerabili-ties

* Prioritize and implement appropriate actions to address the vulnerabilities

* Verify and validate the security posture and compliance of the updated information sys-tem

Therefore, the primary objective of performing a vulnerability assessment following a business system update is to review the effectiveness of controls that are designed to ensure the confidentiality, integrity, and availability of the information system and its data. The other options are not the primary objectives of performing a vulnerability as-sessment following a business system update. Determining operational losses is not an objective, but rather a possible consequence of not performing a vulnerability as-sessment or not addressing the identified vulnerabilities. Improving the change control process is not an objective, but rather a possible outcome of performing a vulnerability assessment and incorporating its results and recommendations into the change man-agement cycle. Updating the threat landscape is not an objective, but rather a prereq-uisite for performing a vulnerability assessment that requires using up-to-date sources of threat intelligence and vulnerability information.

Reference: 1: Vulnerability As-sessment - NIST 2: System Update - Techopedia : Vulnerability Assessment vs Penetra-tion Testing - Imperva : Change Control Process - NIST : Threat Landscape - NIST

asked 01/10/2024
Christopher Horting
41 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first