Certified Information Systems Security Professional CISSP · Free Practice Question Medium

Question 16

After conducting a thorough audit of your organization’s security processes, you are now preparing for an external audit by a third-party assessor. Which of the following actions would BEST prepare the organization for the upcoming external audit?
  • A Conducting a pre-audit review and remediating any identified security gaps before the external audit.
  • B Limiting the external audit to only certain departments to reduce its scope.
  • C Temporarily disabling non-critical security controls to streamline the audit process.
  • D Assigning junior staff members to provide documentation to the external auditors.
Reveal correct answer

Correct answer: A

Explanation

OBJ. 6.5 - Conducting a pre-audit review and addressing any security gaps ensures that the organization is fully prepared for the external audit, reducing the likelihood of critical issues being discovered during the audit process. Disabling controls, assigning junior staff, or limiting the audit’s scope could negatively affect the outcome and lead to non-compliance or other issues being overlooked. For support or reporting issues, include Question ID: 67d9692cda28fa705a58218a in your ticket. Thank you.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need