ISO-IEC-27001-LEAD-AUDITOR · Question #207
An organization does not check the source code of the updated version of an application when it is updated automatically. Thus, the application may be open to unauthorized modifications. This…
The correct answer is C. Vulnerability, (2) integrity. A vulnerability is a weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source. In this case, not checking the source code of an updated application can lead to unauthorized modifications, thus…
Question
An organization does not check the source code of the updated version of an application when it is updated automatically. Thus, the application may be open to unauthorized modifications. This represents a _________________ that may impact information ___________________
Options
- AThreat, (2) confidentiality
- BRisk, (2) availability
- CVulnerability, (2) integrity
How the community answered
(55 responses)- A18% (10)
- B7% (4)
- C75% (41)
Explanation
A vulnerability is a weakness in an information system, system security procedures, internal controls, or implementation that could be exploited by a threat source. In this case, not checking the source code of an updated application can lead to unauthorized modifications, thus representing a vulnerability that may impact the integrity of the information, as integrity refers to the accuracy and completeness of the information.
Topics
Community Discussion
No community discussion yet for this question.