312-50V11 · Question #702
To maintain compliance with regulatory requirements, a security audit of the systems on a network must be performed to determine their compliance with security policies. Which one of the following too
The correct answer is D. Vulnerability scanner. A vulnerability scanner is the appropriate tool for compliance audits because it systematically checks systems against known security weaknesses and policy benchmarks.
Question
To maintain compliance with regulatory requirements, a security audit of the systems on a network must be performed to determine their compliance with security policies. Which one of the following tools would most likely be used in such an audit?
Options
- AProtocol analyzer
- BIntrusion Detection System
- CPort scanner
- DVulnerability scanner
How the community answered
(32 responses)- A3% (1)
- B3% (1)
- C6% (2)
- D88% (28)
Why each option
A vulnerability scanner is the appropriate tool for compliance audits because it systematically checks systems against known security weaknesses and policy benchmarks.
A protocol analyzer (packet sniffer) captures and decodes network traffic for troubleshooting or analysis but does not assess system configurations or compliance posture.
An Intrusion Detection System monitors network or host activity for malicious behavior in real time but does not perform proactive compliance assessments against security policies.
A port scanner identifies open ports and running services on hosts but does not evaluate whether those systems meet security policy requirements or contain exploitable vulnerabilities.
A vulnerability scanner assesses systems against a database of known vulnerabilities and can be configured to check compliance with specific security policies and regulatory frameworks such as PCI-DSS or HIPAA. It produces detailed reports identifying gaps between the current system state and required security baselines. This makes it the primary tool for determining whether systems meet compliance requirements during a security audit.
Concept tested: Vulnerability scanning for regulatory compliance auditing
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.