Isaca Certified Information Systems Auditor CISA Question # 154 Topic 16 Discussion
CISA Exam Topic 16 Question 154 Discussion:
Question #: 154
Topic #: 16
An IS auditor finds that a key Internet-facing system is vulnerable to attack and that patches are not available. What should the auditor recommend be done FIRST?
A.
Implement a new system that can be patched.
B.
Implement additional firewalls to protect the system.
The first step in addressing a vulnerability is to evaluate the associated risk, which involves assessing the likelihood and impact of a potential exploit. Based on the risk assessment, the appropriate mitigation strategy can be determined, such as implementing a new system, addingfirewalls, or decommissioning the server. References: ISACA CISA Review Manual 27th Edition, page 280
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit