nerdexam
Isaca

CISM · Question #577

A vulnerability assessment reveals endpoints have unapproved open ports. Which of the following should the information security manager do FIRST?

The correct answer is D. Determine the impact of the vulnerability.. When unapproved open ports are discovered, the security manager must first determine the impact - understanding what data, systems, or operations are at risk - because this assessment drives every subsequent decision about priority, resources, and response urgency. Without knowin

Submitted by jian89· Apr 18, 2026Information Security Risk Management

Question

A vulnerability assessment reveals endpoints have unapproved open ports. Which of the following should the information security manager do FIRST?

Options

  • AShut down all vulnerable devices.
  • BIdentify the root cause of the vulnerability.
  • CInform senior management of the vulnerability.
  • DDetermine the impact of the vulnerability.

How the community answered

(37 responses)
  • A
    3% (1)
  • B
    5% (2)
  • C
    14% (5)
  • D
    78% (29)

Explanation

When unapproved open ports are discovered, the security manager must first determine the impact - understanding what data, systems, or operations are at risk - because this assessment drives every subsequent decision about priority, resources, and response urgency. Without knowing impact, you cannot make informed choices about what to do next.

Why the distractors are wrong:

  • A (Shut down devices) is premature and potentially disruptive; shutting down systems without understanding impact could cause more business harm than the vulnerability itself.
  • B (Identify root cause) is important but comes after impact is understood - you need to know how bad it is before investing in root cause analysis.
  • C (Inform senior management) is also necessary, but you should have impact data in hand before escalating so you can give leadership meaningful information, not just an alert.

Memory tip: Think of it as triage - a doctor doesn't run tests (root cause) or call the board (notify management) before assessing how sick the patient is (impact). Impact determination is always the lens that focuses everything else in a risk-based security framework like ISACA's.

Topics

#Vulnerability Management#Risk Assessment#Impact Analysis#Security Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice