312-50V11 · Question #804
When a security analyst prepares for the formal security assessment, what of the following should be done in order to determine inconsistencies in the secure assets database and verify that system is
The correct answer is A. Data items and vulnerability scanning. To find inconsistencies in an asset database and verify compliance with a minimum security baseline, an analyst must enumerate data items (asset inventory) and run vulnerability scans against those assets. This combination identifies gaps between what is documented and the actual
Question
When a security analyst prepares for the formal security assessment, what of the following should be done in order to determine inconsistencies in the secure assets database and verify that system is compliant to the minimum security baseline?
Options
- AData items and vulnerability scanning
- BInterviewing employees and network engineers
- CReviewing the firewalls configuration
- DSource code review
How the community answered
(51 responses)- A71% (36)
- B18% (9)
- C4% (2)
- D8% (4)
Why each option
To find inconsistencies in an asset database and verify compliance with a minimum security baseline, an analyst must enumerate data items (asset inventory) and run vulnerability scans against those assets. This combination identifies gaps between what is documented and the actual security posture.
Reviewing data items - the asset inventory - establishes a ground truth of what systems, configurations, and data exist in the environment, making inconsistencies in the secure assets database visible. Pairing this with vulnerability scanning then measures each asset against the minimum security baseline, flagging any system that fails to meet required patch levels, configurations, or controls. Together these two activities directly fulfill both objectives stated in the question.
Interviewing employees and network engineers provides qualitative, anecdotal information useful for scoping assessments but does not systematically enumerate asset inconsistencies or produce measurable compliance results.
Reviewing firewall configurations is a targeted control review for network perimeter security and does not comprehensively verify the broader asset database or compliance posture across all system types.
Source code review is an application-layer security activity focused on identifying software vulnerabilities in code, and does not address asset inventory accuracy or system-level baseline compliance.
Concept tested: Asset inventory and vulnerability scanning for baseline compliance
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-115.pdf
Topics
Community Discussion
No community discussion yet for this question.