nerdexam
Isaca

CISM · Question #642

Which of the following is the MOST effective way to identify weaknesses in security controls?

The correct answer is D. Conduct periodic red team exercises. Red team exercises involve skilled adversaries actively attempting to breach security controls using real-world attack techniques, tools, and tactics. This adversarial approach uncovers practical, exploitable weaknesses in actual controls that theoretical reviews or passive monit

Submitted by yasin.bd· Apr 18, 2026Information Security Program Development and Management

Question

Which of the following is the MOST effective way to identify weaknesses in security controls?

Options

  • ACompare audit results against industry benchmarks
  • BLeverage a SIEM system
  • CPerform tabletop exercises
  • DConduct periodic red team exercises

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    16% (6)
  • C
    5% (2)
  • D
    71% (27)

Explanation

Red team exercises involve skilled adversaries actively attempting to breach security controls using real-world attack techniques, tools, and tactics. This adversarial approach uncovers practical, exploitable weaknesses in actual controls that theoretical reviews or passive monitoring cannot reveal. Option A (comparing audit results to benchmarks) is a passive, retrospective analysis that measures maturity rather than actively probing for exploitable gaps. Option B (SIEM) is a monitoring tool that detects events but does not test whether controls can actually be bypassed. Option C (tabletop exercises) are discussion-based and reveal process and communication gaps but do not test the technical effectiveness of deployed controls.

Topics

#Red Teaming#Security Assessment#Vulnerability Identification#Control Effectiveness

Community Discussion

No community discussion yet for this question.

Full CISM Practice