Back to Questions
CISA
QUESTION #6854
Question 1
An IS auditor finds that penetration testing is conducted annually but identified vulnerabilities are not tracked in a centralized system and remediation is not verified. What is the PRIMARY control weakness?
Correct Answer Explanation
Penetration testing is only valuable if findings lead to remediation. Without centralized tracking and verification, vulnerabilities may not be fixed, fixes may be incomplete, or new vulnerabilities may be introduced. The testing investment provides no actual security improvement if findings are not systematically addressed and verified.
Sign in to join the conversation and share your thoughts.
Log In to Comment