CISA · Question #543
An organization has identified critical vulnerabilities on its information system platforms and has initiated a vulnerability remediation program. Which of the following is an IS auditor's BEST…
The correct answer is B. Define, implement, and enforce system security standards. Defining, implementing, and enforcing system security standards (B) is the best recommendation because it addresses the root cause - it establishes a proactive, repeatable governance framework that prevents vulnerabilities from being introduced in the first place, rather than…
Question
An organization has identified critical vulnerabilities on its information system platforms and has initiated a vulnerability remediation program. Which of the following is an IS auditor's BEST recommendation to prevent new vulnerabilities from being introduced?
Options
- ADiscontinue deployment of new systems until existing vulnerabilities have been remediated.
- BDefine, implement, and enforce system security standards.
- CConduct periodic vulnerability scanning on all information systems.
- DIdentify, review, and procure new security solutions.
How the community answered
(58 responses)- A3% (2)
- B81% (47)
- C5% (3)
- D10% (6)
Explanation
Defining, implementing, and enforcing system security standards (B) is the best recommendation because it addresses the root cause - it establishes a proactive, repeatable governance framework that prevents vulnerabilities from being introduced in the first place, rather than reacting to them after the fact.
Why the distractors fall short:
- A is impractical and operationally disruptive; halting all deployments is not a sustainable control and doesn't prevent future vulnerabilities.
- C is a detective control - scanning finds vulnerabilities that already exist but does nothing to stop new ones from being introduced.
- D is vague and reactive; procuring new tools doesn't systematically prevent vulnerabilities unless those tools are governed by enforceable standards.
Memory tip: Think of the auditor's role as focused on preventive, systemic controls over reactive or one-time fixes. When a question asks how to prevent something from recurring, the answer almost always points to a policy/standard/governance mechanism - not a tool, a pause, or a scan.
Topics
Community Discussion
No community discussion yet for this question.