ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 315 - SY0-701 discussion

Report
Export

The Chief Information Security Officer (CISO) at a large company would like to gain an understanding of how the company's security policies compare to the requirements imposed by external regulators. Which of the following should the CISO use?

A.
Penetration test
Answers
A.
Penetration test
B.
Internal audit
Answers
B.
Internal audit
C.
Attestation
Answers
C.
Attestation
D.
External examination
Answers
D.
External examination
Suggested answer: D

Explanation:

An external examination (also known as an external audit or external review) is the best method for the Chief Information Security Officer (CISO) to gain an understanding of how the company's security policies compare to external regulatory requirements. External examinations are conducted by third-party entities that assess an organization's compliance with laws, regulations, and industry standards.

Penetration tests focus on identifying vulnerabilities, not compliance.

Internal audits assess internal controls but are not impartial or focused on regulatory requirements.

Attestation is a formal declaration but does not involve the actual evaluation of compliance.

asked 02/10/2024
John Hart
47 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first