nerdexam
(ISC)2

CISSP · Question #1445

What is the MOST important goal of conducting security assessments?

The correct answer is B. To discover unmitigated security vulnerabilities, and propose paths for mitigating them. The most important goal of conducting security assessments is to discover unmitigated security vulnerabilities, and propose paths for mitigating them. A security assessment is a process that involves evaluating and testing the security posture and performance of a system or netwo

Submitted by fernanda_arg· Mar 5, 2026Security Assessment and Testing

Question

What is the MOST important goal of conducting security assessments?

Options

  • ATo prepare the organization for an external audit, particularly by a regulatory entity
  • BTo discover unmitigated security vulnerabilities, and propose paths for mitigating them
  • CTo align the security program with organizational risk appetite
  • DTo demonstrate proper function of security controls and processes to senior management

How the community answered

(21 responses)
  • A
    5% (1)
  • B
    71% (15)
  • C
    14% (3)
  • D
    10% (2)

Explanation

The most important goal of conducting security assessments is to discover unmitigated security vulnerabilities, and propose paths for mitigating them. A security assessment is a process that involves evaluating and testing the security posture and performance of a system or network, and identifying and reporting any security vulnerabilities or issues that may pose a security risk. A security assessment can help to discover unmitigated security vulnerabilities, which are the security flaws or weaknesses that have not been detected, reported, or resolved, and that can be exploited by the adversaries to compromise the security of the system or network. A security assessment can also help to propose paths for mitigating the security vulnerabilities, which are the actions or measures that can be taken to eliminate, reduce, or transfer the security risk associated with the security vulnerabilities. Discovering unmitigated security vulnerabilities, and proposing paths for mitigating them, is the most important goal of conducting security assessments, as it can help to improve the security level and quality of the system or network, and to prevent or minimize the potential damage or loss caused by the security incidents or

Topics

#Security assessment#Vulnerability management#Risk mitigation#Security program

Community Discussion

No community discussion yet for this question.

Full CISSP Practice