CISA · Question #448
An IS auditor learns that an organization did not conduct any penetration testing over one internet-facing webpage prior to its production deployment. Which of the following is the auditor's BEST cour
The correct answer is D. Meet with IT and the information security team to determine why testing was not completed.. Before flagging a deficiency, the auditor should first understand the context and reasons for the omission, such as alternative controls, risk acceptance decisions, or schedule constraints, by discussing the issue with IT and security. This information gathering informs whether a
Question
An IS auditor learns that an organization did not conduct any penetration testing over one internet-facing webpage prior to its production deployment. Which of the following is the auditor’s BEST course of action?
Options
- ARevise IT security procedures to require penetration tests for internally developed services prior
- BReport a control deficiency, as no penetration test has been conducted and documented.
- CConfirm whether vulnerability scanning was conducted after the webpage was deployed.
- DMeet with IT and the information security team to determine why testing was not completed.
How the community answered
(28 responses)- A18% (5)
- B4% (1)
- C7% (2)
- D71% (20)
Explanation
Before flagging a deficiency, the auditor should first understand the context and reasons for the omission, such as alternative controls, risk acceptance decisions, or schedule constraints, by discussing the issue with IT and security. This information gathering informs whether a formal finding is warranted and what corrective actions are most appropriate.
Topics
Community Discussion
No community discussion yet for this question.