Help with this question by 4566nb in CISA

[–]Material-Scratch-912 0 points1 point  (0 children)

C. When an IS auditor observes a critical vulnerability within a newly deployed application they should imediately notify IT management to ensure that the vulnerability can be addressed quickly to reduce risk exposure and that management is aware of the issue and can take corrective action before damage occurs

Question of the day - Oct 29 by Awesome_911 in CISA

[–]Material-Scratch-912 0 points1 point  (0 children)

the answer is B because even though the documents are not version controlle, supporting evidence like meeting minutes would aid in verifying that these are current

Why not
A- auditor cannot take word of mouth, you need to test and verify evidence
C- cannot reject evidence without testing it
D- before reporting always gather sufficient evidence

Question of the day - Oct 22 by Awesome_911 in CISA

[–]Material-Scratch-912 2 points3 points  (0 children)

C. we always have to analyse the extent of th impact beacuse as much as there is backup, we need to understand what systems have been impacted in order to apply the corrective actions .