Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.
An IS auditor notes that not all security tests were completed for an online sales system recently promoted to production. Which of the following is the auditor's BEST course of action?
A.
Determine exposure to the business.
B.
Increase monitoring for security incidents.
C.
Hire a third party to perform security testing.
My thoughts - Option A makes sense if question is about "Next" course of action.
Option B makes sense if question is about "Best" course of action.. Please correct if wrong..
While increasing monitoring for security incidents (option B) is important, it is more reactive than proactive and does not directly address the underlying issue of incomplete security testing. Determining exposure to the business provides a more comprehensive understanding of the potential risks and allows for targeted mitigation efforts. Therefore, it is the best course of action for the IS auditor in this scenario.
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Infysenthil
1 day agoSwallows
1 month, 1 week agotakuanism
5 months, 2 weeks agokGiGa
7 months, 2 weeks agoJONESKA
11 months, 3 weeks agom4s7er
1 year, 5 months agoziutek_
1 year, 6 months agoMunaM
1 year, 10 months agogomboragchaa
1 year, 6 months agozuchwaly
1 year, 8 months ago