Certified Information Security Manager CISM · Free Practice Question Medium
Question 116
What source among the options provides the most valuable information for identifying gaps in security controls on an application server?
- A A. Security policy documentation
- B B. User access logs
- C C. Change management records
- D D. Penetration testing
Reveal correct answer
Correct answer: D
Explanation
Correct Answer: D. Penetration testing Explanation: The most valuable source for identifying gaps in security controls on an application server is penetration testing. Penetration testing involves simulating real-world attacks to assess the effectiveness of security measures. It provides in-depth insights into potential vulnerabilities and weaknesses in security controls, helping the Information Security Manager identify areas for improvement and enhance the overall security posture of the application server. While security policy documentation, user access logs, and change management records contribute to security, penetration testing offers a proactive and comprehensive evaluation of the security controls' efficacy.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
