CGRC · Question #320
One of the primary goals in conducting analysis of the test results from a scan during Security Control Assessment (SCA) is to Response:
The correct answer is A. Categorize vulnerabilities. A primary goal of analyzing scan results during a Security Control Assessment is to categorize identified vulnerabilities by severity and potential impact to aid in risk management and remediation efforts.
Question
One of the primary goals in conducting analysis of the test results from a scan during Security Control Assessment (SCA) is to Response:
Options
- ACategorize vulnerabilities
- BDetermine threats to the system
- CIdentify false negative findings
- DValidate system boundaries
How the community answered
(26 responses)- A88% (23)
- B4% (1)
- C8% (2)
Why each option
A primary goal of analyzing scan results during a Security Control Assessment is to categorize identified vulnerabilities by severity and potential impact to aid in risk management and remediation efforts.
When test results from a security scan are analyzed during a Security Control Assessment (SCA), a key objective is to categorize the identified vulnerabilities. This categorization typically involves assigning a severity level (e.g., critical, high, medium, low) to each vulnerability, which helps prioritize remediation actions and inform the overall risk assessment.
Determining threats to the system is typically part of a threat modeling process or risk assessment that precedes or runs in parallel with SCA, not the primary goal of analyzing scan results, which focuses on identifying system weaknesses.
While identifying false negatives (unreported vulnerabilities) is a desirable outcome of a thorough assessment, the primary and immediate goal of analyzing the initial scan results is to understand and categorize what the scan explicitly found.
Validating system boundaries is generally part of the initial system definition and documentation review in an SCA, rather than a direct outcome of analyzing scan results for technical vulnerabilities.
Concept tested: Vulnerability analysis in SCA
Source: https://csrc.nist.gov/glossary/term/vulnerability-analysis
Topics
Community Discussion
No community discussion yet for this question.