nerdexam
EC-Council

512-50 · Question #127

A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should…

The correct answer is C. Review the recommendations and follow up to see if audit implemented the changes. See the full explanation below for the reasoning.

Question

A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old. After reading it, what should be the CISO's FIRST priority?

Options

  • AHave internal audit conduct another audit to see what has changed.
  • BContract with an external audit company to conduct an unbiased audit
  • CReview the recommendations and follow up to see if audit implemented the changes
  • DMeet with audit team to determine a timeline for corrections

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    5% (1)
  • C
    73% (16)
  • D
    18% (4)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice