nerdexam
GAQM

CPEH-001 · Question #456

During a security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?

The correct answer is A. Identify and evaluate existing practices. The auditor should first evaluated existing policies and practices to identify problem areas and

Introduction to Ethical Hacking and Information Security

Question

During a security audit of IT processes, an IS auditor found that there were no documented security procedures. What should the IS auditor do?

Options

  • AIdentify and evaluate existing practices
  • BCreate a procedures document
  • CConduct compliance testing
  • DTerminate the audit

How the community answered

(66 responses)
  • A
    83% (55)
  • B
    9% (6)
  • C
    3% (2)
  • D
    5% (3)

Explanation

The auditor should first evaluated existing policies and practices to identify problem areas and

Topics

#security audit#IS auditing#security procedures#compliance

Community Discussion

No community discussion yet for this question.

Full CPEH-001 Practice