CISA Exam QuestionsBrowse all questions from this exam

CISA Exam - Question 470


Which of the following is the GREATEST risk associated with conducting penetration testing on a business-critical application production environment?

Show Answer
Correct Answer: BC

Conducting penetration testing on a business-critical application production environment can pose several risks. However, the greatest risk is that data integrity may become compromised. If data integrity is compromised, it can lead to severe issues including corruption of critical business data, which can disrupt operations, cause financial losses, and damage the credibility of the organization. These impacts are generally more severe than differences in test results, lack of prior notification to system owners, or non-adherence to audit standards.

Discussion

7 comments
Sign in to comment
BabaPOption: B
May 2, 2023

Answer is B

MunaMOption: B
Sep 7, 2022

I think answer is B

StaanleeOption: B
Dec 8, 2022

B is the right answer.

DeeplaxmiOption: C
Sep 14, 2022

I think C is correct as system owners approval is necessary before penetration tests.

takuanismOption: B
Jan 12, 2024

It should be B. It is more important than C, from the perspective of data integrity

1899f17Option: B
Jan 29, 2024

B is correct

SwallowsOption: B
Jun 9, 2024

While system owners not being informed in advance (option C) is also a concern, it typically does not pose as great a risk as compromising data integrity. System owners not being informed may lead to operational issues or conflicts during the testing process, but it's unlikely to have the same level of impact as data integrity breaches in a business-critical application production environment.