nerdexam
(ISC)2

CISSP · Question #1052

Which audit type is MOST appropriate for evaluating the effectiveness of a security program?

The correct answer is B. Assessment. The audit type that is most appropriate for evaluating the effectiveness of a security program is assessment. Assessment is a type of audit that measures the performance, maturity, or compliance of a security program against a set of standards, criteria, or objectives. Assessment

Submitted by tyler.j· Mar 5, 2026Security Assessment and Testing

Question

Which audit type is MOST appropriate for evaluating the effectiveness of a security program?

Options

  • AThreat
  • BAssessment
  • CAnalysis
  • DValidation

How the community answered

(28 responses)
  • A
    4% (1)
  • B
    93% (26)
  • C
    4% (1)

Explanation

The audit type that is most appropriate for evaluating the effectiveness of a security program is assessment. Assessment is a type of audit that measures the performance, maturity, or compliance of a security program against a set of standards, criteria, or objectives. Assessment can help to identify the strengths, weaknesses, gaps, or risks of a security program, and to provide recommendations for improvement or remediation. Assessment can also help to demonstrate the value, benefits, or return on investment of a security program to the stakeholders, customers, or regulators. Threat, analysis, or validation are not the audit types that are most appropriate for evaluating the effectiveness of a security program. Threat is a type of audit that identifies the potential sources, methods, or impacts of an attack or a breach on a system or an organization. Analysis is a type of audit that examines the data, information, or evidence collected from a system or an organization, and that provides insights, conclusions, or solutions. Validation is a type of audit that verifies the accuracy, completeness, or correctness of a system or an organization, and that confirms that it meets the requirements, specifications, or

Topics

#security audit#security program evaluation#effectiveness assessment

Community Discussion

No community discussion yet for this question.

Full CISSP Practice