CISM · Question #803
An organization has implemented controls to mitigate risks resulting from identified vulnerabilities in an application. Which of the following is the BEST way to verify all weaknesses have been addres
The correct answer is C. Perform a vulnerability assessment.. After implementing controls, performing a vulnerability assessment is the best way to verify that all previously identified weaknesses have been addressed. The CISM Review Manual specifies that vulnerability assessments systematically scan for known vulnerabilities and confirm re
Question
An organization has implemented controls to mitigate risks resulting from identified vulnerabilities in an application. Which of the following is the BEST way to verify all weaknesses have been addressed?
Options
- AConduct an internal audit.
- BConduct penetration testing.
- CPerform a vulnerability assessment.
- DPrepare compensating controls.
How the community answered
(49 responses)- A4% (2)
- B6% (3)
- C71% (35)
- D18% (9)
Explanation
After implementing controls, performing a vulnerability assessment is the best way to verify that all previously identified weaknesses have been addressed. The CISM Review Manual specifies that vulnerability assessments systematically scan for known vulnerabilities and confirm remediation effectiveness. Penetration testing is valuable but is typically used to exploit vulnerabilities, not comprehensively verify their remediation as efficiently as vulnerability
Topics
Community Discussion
No community discussion yet for this question.