ExamGecko
Question list
Search
Search

Question 498 - CISM discussion

Report
Export

Which of the following provides the MOST useful information for identifying security control gaps on an application server?

A.
Risk assessments
Answers
A.
Risk assessments
B.
Threat models
Answers
B.
Threat models
C.
Penetration testing
Answers
C.
Penetration testing
D.
Internal audit reports
Answers
D.
Internal audit reports
Suggested answer: C

Explanation:

Penetration testing is the most useful method for identifying security control gaps on an application server because it simulates real-world attacks and exploits the vulnerabilities and weaknesses of the application server. Penetration testing can reveal the actual impact and risk of the security control gaps, and provide recommendations for remediation and improvement.

asked 01/10/2024
Conceicao Damasceno
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first