When an employee exploits avulnerability, the most appropriate audit is aforensic audit, as it focuses oninvestigating and documenting security incidentsfor legal or disciplinary action.
Option A (Incorrect):Acompliance auditensures adherence to policies but does not investigate incidents in detail.
Option B (Incorrect):Application security testinghelps identify vulnerabilities but does not addressemployee misuse.
Option C (Correct):Aforensic auditgathersdigital evidence, determines how the exploit occurred, and ensures legal compliance in the investigation.
Option D (Incorrect):Penetration testingidentifies weaknesses but does notanalyze past incidents.
[Reference:ISACA CISA Review Manual –Domain 5: Protection of Information Assets– Covers forensic investigations, digital evidence collection, and security incident response., , , , , , , ]
Submit