Câu 412: CISA: Certified Information Systems Auditor
During a review of an organization's network threat response process, the IS auditor noticed that the majority of alerts were closed without resolution. Management responded that those alerts were unworkable due to lack of actionable intelligence, and therefore the support team is allowed to close them. What is the BE…
Nội dung câu hỏi
During a review of an organization's network threat response process, the IS auditor noticed that the majority of alerts were closed without resolution. Management responded that those alerts were unworkable due to lack of actionable intelligence, and therefore the support team is allowed to close them. What is the BEST way for the auditor to address this situation?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Further review closed unactioned alerts to identify mishandling of threats. — đáp án hiện tại
- B. Reopen unactioned alerts and report to the audit committee.
- C. Recommend that management enhance the policy and improve threat awareness training.
- D. Omit the finding from the report as this practice is in compliance with the current policy.
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.