nerdexam
Isaca

CISM · Question #194

When performing vulnerability scans, the information security team finds multiple systems that do not match security configuration standards. Which of the following should be done FIRST?

The correct answer is C. Determine the level of risk.. The first step when systems are found to not match security configuration standards is to determine the level of risk. This assessment helps prioritize the response based on the potential impact of the noncompliance and guides the next steps, such as remediation or further

Submitted by yasin.bd· Apr 18, 2026Information Security Risk Management

Question

When performing vulnerability scans, the information security team finds multiple systems that do not match security configuration standards. Which of the following should be done FIRST?

Options

  • AExecute a policy exception for the violation.
  • BTake the systems offline.
  • CDetermine the level of risk.
  • DDiscuss the noncompliance with senior management.

How the community answered

(46 responses)
  • A
    2% (1)
  • B
    7% (3)
  • C
    80% (37)
  • D
    11% (5)

Explanation

The first step when systems are found to not match security configuration standards is to determine the level of risk. This assessment helps prioritize the response based on the potential impact of the noncompliance and guides the next steps, such as remediation or further

Topics

#Risk Assessment#Vulnerability Management#Security Configuration#Compliance

Community Discussion

No community discussion yet for this question.

Full CISM Practice