712-50 Exam QuestionsBrowse all questions from this exam

712-50 Exam - Question 69


A new CISO just started with a company and on the CISO's desk is the last complete Information Security Management audit report. The audit report is over two years old.

After reading it, what should be your first priority?

Show Answer
Correct Answer: C

Given that the audit report is over two years old, the most prudent first step is to have an internal audit conducted again to assess the current state of Information Security Management. This will provide the new CISO with up-to-date information on what has changed, allowing for more informed decision-making on subsequent actions and adjustments that may be needed.

Discussion

6 comments
Sign in to comment
jraaf
Dec 29, 2022

It should be C

Kentish
Apr 2, 2023

Audit wouldn't be implementing the changes, it should be reviewing the actions with the internal team to see what they have implemented.

RC2073Option: A
Sep 4, 2023

A is correct. I confirmed the same answer on another website.

Emporeo
Mar 6, 2024

C audit does not implement changes

alfaMegatronOption: C
Aug 18, 2024

Audit does not implement changes

BettoxicityOption: C
Dec 18, 2024

Why not A: While reviewing recommendations is valuable, it doesn't provide insights into new risks or changes that have occurred since the last audit.