CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 718


An IS auditor notes that not all security tests were completed for an online sales system recently promoted to production. Which of the following is the auditor's

BEST course of action?

Show Answer
Correct Answer: AD

When an IS auditor notes that not all security tests were completed for an online sales system recently promoted to production, the primary concern should be to assess the risk that this incomplete testing poses to the business. Determining the exposure to the business helps in understanding the potential impact of any security vulnerabilities and informs the decision-making process for any remedial actions. It provides a risk-based approach to address the issue effectively.

Discussion

8 comments
Sign in to comment
MunaMOption: A
Sep 7, 2022

Do you think answer should be A?

zuchwaly
Oct 19, 2022

yes, I think so.

gomboragchaa
Dec 15, 2022

Me too :D

ziutek_Option: A
Dec 18, 2022

Only A

m4s7erOption: A
Jan 27, 2023

i think answer is A

JONESKAOption: A
Jul 20, 2023

Should be A

kGiGaOption: B
Nov 25, 2023

Why not increase security monitoring first? Given that the security tests have not completed, the business exposure level must be greater than zero.

takuanismOption: B
Jan 20, 2024

should be B, I guess.

SwallowsOption: A
May 25, 2024

While increasing monitoring for security incidents (option B) is important, it is more reactive than proactive and does not directly address the underlying issue of incomplete security testing. Determining exposure to the business provides a more comprehensive understanding of the potential risks and allows for targeted mitigation efforts. Therefore, it is the best course of action for the IS auditor in this scenario.

InfysenthilOption: B
Jul 7, 2024

My thoughts - Option A makes sense if question is about "Next" course of action. Option B makes sense if question is about "Best" course of action.. Please correct if wrong..