ExamGecko
Question list
Search
Search

Question 654 - CISM discussion

Report
Export

Which of the following is the BEST starting point for a newly hired information security manager who has been tasked with identifying and addressing network vulnerabilities?

A.
Controls analysis
Answers
A.
Controls analysis
B.
Emerging risk review
Answers
B.
Emerging risk review
C.
Penetration testing
Answers
C.
Penetration testing
D.
Traffic monitoring
Answers
D.
Traffic monitoring
Suggested answer: C

Explanation:

The best starting point for a newly hired information security manager who has been tasked with identifying and addressing network vulnerabilities is C. Penetration testing. This is because penetration testing is a method of simulating real-world attacks on a network to evaluate its security posture and identify any weaknesses or gaps that could be exploited by malicious actors. Penetration testing can help the information security manager to assess the effectiveness of the existing controls, prioritize the remediation efforts, and demonstrate compliance with the relevant standards and regulations. Penetration testing can also provide valuable insights into the network architecture, configuration, and behavior, as well as the potential impact and likelihood of different types of attacks.

Reference = CISM Review Manual 15th Edition, Chapter 4, Section 4.2.1, page 2091; CISM Review Questions, Answers & Explanations Manual 9th Edition, Question 50, page 14

asked 01/10/2024
umar raad
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first