CISM · Question #796
An information security team has started work to mitigate findings from a recent penetration test. Which of the following presents the GREATEST risk to the organization?
The correct answer is D. Risk classification of penetration test findings was not performed. The greatest risk comes from not performing risk classification on the findings. Without classification, the organization cannot prioritize remediation efforts, allocate resources effectively, or understand the business impact of the vulnerabilities. "Risk classification helps…
Question
An information security team has started work to mitigate findings from a recent penetration test. Which of the following presents the GREATEST risk to the organization?
Options
- ASome findings were reclassified to low risk after evaluation
- BNot all findings from the penetration test report were fixed
- CThe penetration testing report did not contain any high-risk findings
- DRisk classification of penetration test findings was not performed
How the community answered
(25 responses)- A4% (1)
- B24% (6)
- C12% (3)
- D60% (15)
Explanation
The greatest risk comes from not performing risk classification on the findings. Without classification, the organization cannot prioritize remediation efforts, allocate resources effectively, or understand the business impact of the vulnerabilities. "Risk classification helps determine the priority for mitigating vulnerabilities and enables risk- informed decisions." Even if some findings are unfixed or reclassified, the lack of any classification process undermines the whole risk management effort.
Topics
Community Discussion
No community discussion yet for this question.