CIPT Exam QuestionsBrowse all questions from this exam

CIPT Exam - Question 157


An organization has recently experienced a data breach where large amounts of personal data were compromised. As part of a post-incident review, the privacy technologist wants to analyze available data to understand what vulnerabilities may have contributed to the incident occurring. He learns that a key vulnerability had been flagged by the system but that detective controls were not operating effectively. Which type of web application security risk does this finding most likely point to?

Show Answer
Correct Answer:

Discussion

1 comment
Sign in to comment
SsouravOption: D
Aug 11, 2024

The correct answer is D. Logging and Monitoring Failures. This finding most likely points to logging and monitoring failures, as the vulnerability was flagged by the system, but the detective controls were not operating effectively, preventing the organization from identifying and addressing the issue in a timely manner.