CISM · Question #208
An information security manager is considering options for protecting the data on a web-facing legacy application that cannot be patched. Which of the following would provide the BEST information…
The correct answer is D. Penetration testing. Penetration testing provides the BEST evidence of whether compensating controls are actually effective for an unpatched legacy application. Unlike passive logs or rule reviews, penetration testing actively attempts to exploit the vulnerability through the compensating controls…
Question
An information security manager is considering options for protecting the data on a web-facing legacy application that cannot be patched. Which of the following would provide the BEST information about the effectiveness of compensating controls?
Options
- AFirewall rules
- BThreat assessment
- CIntrusion detection system (IDS) logs
- DPenetration testing
How the community answered
(35 responses)- A3% (1)
- B14% (5)
- C9% (3)
- D74% (26)
Explanation
Penetration testing provides the BEST evidence of whether compensating controls are actually effective for an unpatched legacy application. Unlike passive logs or rule reviews, penetration testing actively attempts to exploit the vulnerability through the compensating controls - directly proving whether they work in practice. Firewall rules (A) show configuration intent but not actual effectiveness. A threat assessment (B) identifies risks but doesn't validate controls. IDS logs (C) show detected activity but can't confirm whether undetected attacks would succeed. Only pen testing empirically validates control effectiveness.
Topics
Community Discussion
No community discussion yet for this question.