exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 116 discussion

Actual exam question from Isaca's CISM
Question #: 116
Topic #: 1
[All CISM Questions]

What is the PRIMARY objective of performing a vulnerability assessment following a business system update?

  • A. Improve the change control process.
  • B. Update the threat landscape.
  • C. Determine operational losses.
  • D. Review the effectiveness of controls.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Broesweelies
Highly Voted 1 year, 12 months ago
Selected Answer: D
According to ISACA, the primary objective of performing a vulnerability assessment following a business system update is "D. Review the effectiveness of controls." A vulnerability assessment is a process that aims to identify, assess and prioritize vulnerabilities in an organization's systems, networks and applications. The primary objective of performing a vulnerability assessment following a business system update is to ensure that the new updates have not introduced any new vulnerabilities or weaknesses that could be exploited by attackers. It is important to conduct a vulnerability assessment as part of a continuous monitoring process to identify and address any vulnerabilities that could impact the effectiveness of the implemented controls.
upvoted 13 times
...
xcjxcj
Most Recent 10 months, 3 weeks ago
Selected Answer: B
If the update is security control itself, i prefer D. However i take it as functional update, then answer should be B.
upvoted 1 times
...
oluchecpoint
1 year, 4 months ago
D. Review the effectiveness of controls. After a business system update, it is essential to assess the effectiveness of the controls put in place to secure the updated system. This assessment helps identify any new vulnerabilities introduced during the update process or any weaknesses in the existing security controls. By reviewing the effectiveness of controls, organizations can ensure that their systems remain secure and that any vulnerabilities are promptly identified and remediated. This proactive approach helps prevent security incidents and breaches that could result from overlooked vulnerabilities.
upvoted 1 times
...
Jae_kes
1 year, 7 months ago
Selected Answer: D
The PRIMARY objective of performing a vulnerability assessment following a business system update is to review the effectiveness of controls. By conducting a vulnerability assessment, organizations can identify and assess potential vulnerabilities or weaknesses in the updated system
upvoted 1 times
...
richck102
1 year, 7 months ago
A. Improve the change control process.
upvoted 1 times
...
bambs
1 year, 9 months ago
Selected Answer: D
Performing a vulnerability assessment following a business system update is an important step in ensuring that the updated system is secure and resilient to attacks. The primary objective of this assessment is to review the effectiveness of the controls that have been implemented to mitigate vulnerabilities in the updated system.
upvoted 1 times
...
Prospect57
2 years ago
Selected Answer: B
B is my answer. An updated system/product has the potential to increase the attack surface or "threat landscape" of systems.
upvoted 2 times
AlexJacobson
12 months ago
Attack surface and threat landscape are completely different things. Attack surface is related to the asset itself and it's an internal matter, so to speak, while threat landscape is the external thing. You can't affect the threat landscape, it's beyond your control. Attack surface, on the other hand, you can control.
upvoted 1 times
...
...
MyKasala
2 years ago
Selected Answer: B
I guess B
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...