nerdexam
Isaca

CISA · Question #448

An IS auditor learns that an organization did not conduct any penetration testing over one internet-facing webpage prior to its production deployment. Which of the following is the auditor's BEST cour

The correct answer is D. Meet with IT and the information security team to determine why testing was not completed.. Before flagging a deficiency, the auditor should first understand the context and reasons for the omission, such as alternative controls, risk acceptance decisions, or schedule constraints, by discussing the issue with IT and security. This information gathering informs whether a

Submitted by anna_se· Apr 18, 2026Information Systems Acquisition, Development, and Implementation

Question

An IS auditor learns that an organization did not conduct any penetration testing over one internet-facing webpage prior to its production deployment. Which of the following is the auditor’s BEST course of action?

Options

  • ARevise IT security procedures to require penetration tests for internally developed services prior
  • BReport a control deficiency, as no penetration test has been conducted and documented.
  • CConfirm whether vulnerability scanning was conducted after the webpage was deployed.
  • DMeet with IT and the information security team to determine why testing was not completed.

How the community answered

(28 responses)
  • A
    18% (5)
  • B
    4% (1)
  • C
    7% (2)
  • D
    71% (20)

Explanation

Before flagging a deficiency, the auditor should first understand the context and reasons for the omission, such as alternative controls, risk acceptance decisions, or schedule constraints, by discussing the issue with IT and security. This information gathering informs whether a formal finding is warranted and what corrective actions are most appropriate.

Topics

#Penetration Testing#SDLC Security#Auditor Investigation#Control Deficiency

Community Discussion

No community discussion yet for this question.

Full CISA Practice