CISM · Question #204
A penetration test was conducted by an accredited third party. Which of the following should be the information security manager's FIRST course of action?
The correct answer is B. Ensure a risk assessment is performed to evaluate the findings.. Performing a risk assessment is the correct first action because penetration test findings must be evaluated in the context of the organization's risk appetite and business impact before any response is planned - not all vulnerabilities carry equal weight, and prioritization is i
Question
A penetration test was conducted by an accredited third party. Which of the following should be the information security manager's FIRST course of action?
Options
- AProduce a business case to resolve identified issues.
- BEnsure a risk assessment is performed to evaluate the findings.
- CUpdate intrusion prevention system (IPS) settings.
- DEnsure vulnerabilities found are resolved within acceptable timeframes.
How the community answered
(29 responses)- A17% (5)
- B45% (13)
- C31% (9)
- D7% (2)
Explanation
Performing a risk assessment is the correct first action because penetration test findings must be evaluated in the context of the organization's risk appetite and business impact before any response is planned - not all vulnerabilities carry equal weight, and prioritization is impossible without that context.
Why the distractors are wrong:
- A (business case): A business case for remediation can only be built after you understand the risk level of each finding - it's a downstream activity.
- C (update IPS settings): This is a premature, tactical jump to a specific technical control before understanding which findings actually warrant it.
- D (resolve within acceptable timeframes): Ensuring timely resolution is valid, but what timeframe is acceptable depends on the risk rating - you need the assessment first to set that priority.
Memory tip: Use the sequence "Assess → Plan → Act." The manager's job is governance, not immediate firefighting - the first move is always to understand risk before deciding how (or whether) to respond.
Topics
Community Discussion
No community discussion yet for this question.