nerdexam
EC-Council

312-50V11 · Question #702

To maintain compliance with regulatory requirements, a security audit of the systems on a network must be performed to determine their compliance with security policies. Which one of the following too

The correct answer is D. Vulnerability scanner. A vulnerability scanner is the appropriate tool for compliance audits because it systematically checks systems against known security weaknesses and policy benchmarks.

Vulnerability Analysis

Question

To maintain compliance with regulatory requirements, a security audit of the systems on a network must be performed to determine their compliance with security policies. Which one of the following tools would most likely be used in such an audit?

Options

  • AProtocol analyzer
  • BIntrusion Detection System
  • CPort scanner
  • DVulnerability scanner

How the community answered

(32 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    6% (2)
  • D
    88% (28)

Why each option

A vulnerability scanner is the appropriate tool for compliance audits because it systematically checks systems against known security weaknesses and policy benchmarks.

AProtocol analyzer

A protocol analyzer (packet sniffer) captures and decodes network traffic for troubleshooting or analysis but does not assess system configurations or compliance posture.

BIntrusion Detection System

An Intrusion Detection System monitors network or host activity for malicious behavior in real time but does not perform proactive compliance assessments against security policies.

CPort scanner

A port scanner identifies open ports and running services on hosts but does not evaluate whether those systems meet security policy requirements or contain exploitable vulnerabilities.

DVulnerability scannerCorrect

A vulnerability scanner assesses systems against a database of known vulnerabilities and can be configured to check compliance with specific security policies and regulatory frameworks such as PCI-DSS or HIPAA. It produces detailed reports identifying gaps between the current system state and required security baselines. This makes it the primary tool for determining whether systems meet compliance requirements during a security audit.

Concept tested: Vulnerability scanning for regulatory compliance auditing

Source: https://csrc.nist.gov/publications/detail/sp/800-115/final

Topics

#vulnerability scanner#security audit#compliance#network assessment

Community Discussion

No community discussion yet for this question.

Full 312-50V11 Practice