nerdexam
Isaca

CISM · Question #208

An information security manager is considering options for protecting the data on a web-facing legacy application that cannot be patched. Which of the following would provide the BEST information…

The correct answer is D. Penetration testing. Penetration testing provides the BEST evidence of whether compensating controls are actually effective for an unpatched legacy application. Unlike passive logs or rule reviews, penetration testing actively attempts to exploit the vulnerability through the compensating controls…

Submitted by sofia.br· Apr 18, 2026Information Security Risk Management

Question

An information security manager is considering options for protecting the data on a web-facing legacy application that cannot be patched. Which of the following would provide the BEST information about the effectiveness of compensating controls?

Options

  • AFirewall rules
  • BThreat assessment
  • CIntrusion detection system (IDS) logs
  • DPenetration testing

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    14% (5)
  • C
    9% (3)
  • D
    74% (26)

Explanation

Penetration testing provides the BEST evidence of whether compensating controls are actually effective for an unpatched legacy application. Unlike passive logs or rule reviews, penetration testing actively attempts to exploit the vulnerability through the compensating controls - directly proving whether they work in practice. Firewall rules (A) show configuration intent but not actual effectiveness. A threat assessment (B) identifies risks but doesn't validate controls. IDS logs (C) show detected activity but can't confirm whether undetected attacks would succeed. Only pen testing empirically validates control effectiveness.

Topics

#Compensating controls#Security testing#Penetration testing#Legacy systems security

Community Discussion

No community discussion yet for this question.

Full CISM Practice