CISM · Question #933
Which of the following is an information security manager's BEST course of action when a penetration test reveals a security exposure due to a firewall that is not configured correctly?
The correct answer is A. Ensure a plan with milestones is developed. A penetration test finding is typically handled through remediation, not incident response. The best action is to ensure a corrective plan with milestones is developed so the misconfiguration is fixed, tracked, and validated.
Question
Which of the following is an information security manager's BEST course of action when a penetration test reveals a security exposure due to a firewall that is not configured correctly?
Options
- AEnsure a plan with milestones is developed.
- BImplement a distributed denial of service (DDoS) control.
- CDefine new key performance indicators (KPIs).
- DEngage the incident response team.
How the community answered
(43 responses)- A81% (35)
- B9% (4)
- C2% (1)
- D7% (3)
Explanation
A penetration test finding is typically handled through remediation, not incident response. The best action is to ensure a corrective plan with milestones is developed so the misconfiguration is fixed, tracked, and validated.
Topics
Community Discussion
No community discussion yet for this question.