Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 Exam CISSP Topic 5 Question 97 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 97
Topic #: 5
[All CISSP Questions]

In setting expectations when reviewing the results of a security test, which of the following statements is MOST important to convey to reviewers?

Show Suggested Answer Hide Answer
Suggested Answer: B

The most important statement to convey to reviewers when setting expectations for reviewing the results of a security test is that the results of the tests represent a point-in-time assessment of the target(s). A security test is a process of evaluating and measuring the security posture and performance of an information system or a network, by using various tools, techniques, and methods, such as vulnerability scanning, penetration testing, or security auditing. The results of a security test reflect the security state of the target(s) at the time of the test, and they may not be valid or accurate for a different time period, as the security environment and conditions may change due to various factors, such as new threats, patches, updates, or configurations. Therefore, reviewers should understand that the results of a security test are not definitive or permanent, but rather indicative or temporary, and that they should be interpreted and used accordingly. The statement that the target's security posture cannot be further compromised is not true, as a security test does not guarantee or ensure the security of the target(s), but rather identifies and reports the security issues or weaknesses that may exist. The statement that the accuracy of testing results can be greatly improved if the target(s) are properly hardened is not relevant, as a security test is not meant to improve the accuracy of the results, but rather to assess the security of the target(s), and hardening the target(s) before the test may not reflect the actual or realistic security posture of the target(s). The statement that the deficiencies identified can be corrected immediately is not realistic, as a security test may identify various types of deficiencies that may require different levels of effort, time, and resources to correct, and some deficiencies may not be correctable at all, due to technical, operational, or financial constraints.


Contribute your Thoughts:

Louisa
20 days ago
I'm going with C. If the target is properly hardened, the results will be much more accurate. Gotta love that attention to detail!
upvoted 0 times
...
Dick
21 days ago
Agreed, B is the way to go. You don't want the reviewers to think the issues are permanent, right? Time to upgrade that security system!
upvoted 0 times
Bethanie
1 days ago
B) The results of the tests represent a point-in-time assessment of the target(s).
upvoted 0 times
...
Launa
8 days ago
A) The target's security posture cannot be further compromised.
upvoted 0 times
...
...
Erick
1 months ago
Option B is the most important - security is a moving target, and these results only represent a snapshot in time.
upvoted 0 times
Eleni
11 days ago
C) The accuracy of testing results can be greatly improved if the target(s) are properly hardened.
upvoted 0 times
...
Tequila
15 days ago
A) The results of the tests represent a point-in-time assessment of the target(s).
upvoted 0 times
...
...
Devon
1 months ago
I see your point, Jennifer. Properly hardening the target can definitely impact the accuracy of the testing results.
upvoted 0 times
...
Jennifer
1 months ago
I believe C) The accuracy of testing results can be greatly improved if the target(s) are properly hardened is also crucial to convey.
upvoted 0 times
...
Lavera
1 months ago
I agree with Maile, it's important to understand that the results are not static and can change over time.
upvoted 0 times
...
Maile
1 months ago
I think the most important statement to convey is B) The results of the tests represent a point-in-time assessment of the target(s).
upvoted 0 times
...

Save Cancel
az-700  pass4success  az-104  200-301  200-201  cissp  350-401  350-201  350-501  350-601  350-801  350-901  az-720  az-305  pl-300  

Warning: Cannot modify header information - headers already sent by (output started at /pass.php:70) in /pass.php on line 77