Certified Information Systems Security Professional CISSP · Free Practice Question Easy
Question 73
What do we often uncover in our vulnerability scans?
- A The vulnerabilities present on a system
- B The effectiveness of security controls in place
- C The presence of malware on a system
- D The location of confidential documents
Reveal correct answer
Correct answer: A
Explanation
The correct answer: The vulnerabilities present on a system: Vulnerability scans are specifically designed to identify and assess the vulnerabilities present on a system. A vulnerability scan is an inspection of the potential points of exploit in a computer system or network to identify security holes. It does this by using a database of known vulnerabilities and checks systems to see if these vulnerabilities exist. The results of these scans are typically used by IT and cybersecurity professionals to patch and secure systems, ensuring they are protected against known threats. This is the primary purpose of vulnerability scans, and so it is what we would most often uncover when performing these scans. The incorrect answers: The presence of malware on a system: While vulnerability scans can sometimes indirectly suggest the presence of malware by identifying unexpected or abnormal behaviors, they are not primarily designed for malware detection. Malware scans or Antivirus scans, which actively search for malicious software, are the correct tools for identifying the presence of malware. Vulnerability scans primarily identify potential weaknesses that malware might exploit but do not confirm whether malware has indeed been installed on a system. The effectiveness of security controls in place: Vulnerability scans do identify vulnerabilities, but they don't specifically measure the effectiveness of security controls. Security audits and penetration testing (pen tests) are more suited for assessing the efficacy of security measures. These involve a systematic evaluation of an information system's security by measuring how well it conforms to a set of established criteria. They may take into account vulnerability scan results, but they also include evaluation of administrative controls, physical security, and other relevant factors. The location of confidential documents: Vulnerability scans are not designed to locate confidential documents. While they may identify vulnerabilities that could potentially be exploited to access confidential documents, they do not directly find or interact with these documents. Tasks like Data Loss Prevention (DLP) processes, eDiscovery tools, or regular internal audits are better suited for tracking and securing confidential information. These tools and processes actively search for and protect sensitive data throughout an organization's systems.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
