Certified Information Security Manager CISM · Free Practice Question Medium

Question 116

What source among the options provides the most valuable information for identifying gaps in security controls on an application server?
  • A A. Security policy documentation
  • B B. User access logs
  • C C. Change management records
  • D D. Penetration testing
Reveal correct answer

Correct answer: D

Explanation

Correct Answer: D. Penetration testing Explanation: The most valuable source for identifying gaps in security controls on an application server is penetration testing. Penetration testing involves simulating real-world attacks to assess the effectiveness of security measures. It provides in-depth insights into potential vulnerabilities and weaknesses in security controls, helping the Information Security Manager identify areas for improvement and enhance the overall security posture of the application server. While security policy documentation, user access logs, and change management records contribute to security, penetration testing offers a proactive and comprehensive evaluation of the security controls' efficacy.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need