nerdexam
Isaca

CISM · Question #204

A penetration test was conducted by an accredited third party. Which of the following should be the information security manager's FIRST course of action?

The correct answer is B. Ensure a risk assessment is performed to evaluate the findings.. Performing a risk assessment is the correct first action because penetration test findings must be evaluated in the context of the organization's risk appetite and business impact before any response is planned - not all vulnerabilities carry equal weight, and prioritization is i

Submitted by hassan_iq· Apr 18, 2026Information Security Risk Management

Question

A penetration test was conducted by an accredited third party. Which of the following should be the information security manager's FIRST course of action?

Options

  • AProduce a business case to resolve identified issues.
  • BEnsure a risk assessment is performed to evaluate the findings.
  • CUpdate intrusion prevention system (IPS) settings.
  • DEnsure vulnerabilities found are resolved within acceptable timeframes.

How the community answered

(29 responses)
  • A
    17% (5)
  • B
    45% (13)
  • C
    31% (9)
  • D
    7% (2)

Explanation

Performing a risk assessment is the correct first action because penetration test findings must be evaluated in the context of the organization's risk appetite and business impact before any response is planned - not all vulnerabilities carry equal weight, and prioritization is impossible without that context.

Why the distractors are wrong:

  • A (business case): A business case for remediation can only be built after you understand the risk level of each finding - it's a downstream activity.
  • C (update IPS settings): This is a premature, tactical jump to a specific technical control before understanding which findings actually warrant it.
  • D (resolve within acceptable timeframes): Ensuring timely resolution is valid, but what timeframe is acceptable depends on the risk rating - you need the assessment first to set that priority.

Memory tip: Use the sequence "Assess → Plan → Act." The manager's job is governance, not immediate firefighting - the first move is always to understand risk before deciding how (or whether) to respond.

Topics

#Penetration Testing#Risk Assessment#Vulnerability Management#Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice