Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 16
After conducting a thorough audit of your organization’s security processes, you are now preparing for an external audit by a third-party assessor. Which of the following actions would BEST prepare the organization for the upcoming external audit?
- A Conducting a pre-audit review and remediating any identified security gaps before the external audit.
- B Limiting the external audit to only certain departments to reduce its scope.
- C Temporarily disabling non-critical security controls to streamline the audit process.
- D Assigning junior staff members to provide documentation to the external auditors.
Reveal correct answer
Correct answer: A
Explanation
OBJ. 6.5 - Conducting a pre-audit review and addressing any security gaps ensures that the organization is fully prepared for the external audit, reducing the likelihood of critical issues being discovered during the audit process. Disabling controls, assigning junior staff, or limiting the audit’s scope could negatively affect the outcome and lead to non-compliance or other issues being overlooked. For support or reporting issues, include Question ID: 67d9692cda28fa705a58218a in your ticket. Thank you.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
