nerdexam
Isaca

CISA · Question #283

Which of the following approaches BEST enables an IS auditor to detect security vulnerabilities within an application?

The correct answer is A. Threat modelling. Threat modeling is the best approach for detecting security vulnerabilities within an application. It involves identifying potential threats, vulnerabilities, and attack vectors during the design and development stages, allowing for proactive mitigation of risks and strengthening

Submitted by anjalisingh· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

Which of the following approaches BEST enables an IS auditor to detect security vulnerabilities within an application?

Options

  • AThreat modelling
  • BThreat intelligence
  • CConcept mapping
  • DPrototyping

How the community answered

(67 responses)
  • A
    81% (54)
  • B
    10% (7)
  • C
    3% (2)
  • D
    6% (4)

Explanation

Threat modeling is the best approach for detecting security vulnerabilities within an application. It involves identifying potential threats, vulnerabilities, and attack vectors during the design and development stages, allowing for proactive mitigation of risks and strengthening application

Topics

#Threat Modeling#Application Security#Vulnerability Detection#IS Audit Techniques

Community Discussion

No community discussion yet for this question.

Full CISA Practice