nerdexam
(ISC)2

CGRC · Question #320

One of the primary goals in conducting analysis of the test results from a scan during Security Control Assessment (SCA) is to Response:

The correct answer is A. Categorize vulnerabilities. A primary goal of analyzing scan results during a Security Control Assessment is to categorize identified vulnerabilities by severity and potential impact to aid in risk management and remediation efforts.

Assessment/Audit of Security and Privacy Controls

Question

One of the primary goals in conducting analysis of the test results from a scan during Security Control Assessment (SCA) is to Response:

Options

  • ACategorize vulnerabilities
  • BDetermine threats to the system
  • CIdentify false negative findings
  • DValidate system boundaries

How the community answered

(26 responses)
  • A
    88% (23)
  • B
    4% (1)
  • C
    8% (2)

Why each option

A primary goal of analyzing scan results during a Security Control Assessment is to categorize identified vulnerabilities by severity and potential impact to aid in risk management and remediation efforts.

ACategorize vulnerabilitiesCorrect

When test results from a security scan are analyzed during a Security Control Assessment (SCA), a key objective is to categorize the identified vulnerabilities. This categorization typically involves assigning a severity level (e.g., critical, high, medium, low) to each vulnerability, which helps prioritize remediation actions and inform the overall risk assessment.

BDetermine threats to the system

Determining threats to the system is typically part of a threat modeling process or risk assessment that precedes or runs in parallel with SCA, not the primary goal of analyzing scan results, which focuses on identifying system weaknesses.

CIdentify false negative findings

While identifying false negatives (unreported vulnerabilities) is a desirable outcome of a thorough assessment, the primary and immediate goal of analyzing the initial scan results is to understand and categorize what the scan explicitly found.

DValidate system boundaries

Validating system boundaries is generally part of the initial system definition and documentation review in an SCA, rather than a direct outcome of analyzing scan results for technical vulnerabilities.

Concept tested: Vulnerability analysis in SCA

Source: https://csrc.nist.gov/glossary/term/vulnerability-analysis

Topics

#Security Control Assessment#Vulnerability Analysis#Scan Results

Community Discussion

No community discussion yet for this question.

Full CGRC Practice