CISSP Practice Question (Domain 6: Security Assessment and Testing)
Your organization completed a penetration test that found critical vulnerabilities in a payment processing system. The business unit owner wants to delay remediation until after the holiday revenue peak, citing potential downtime. What should you do FIRST?
A. Override the business unit and enforce immediate remediation of all critical findings
B. Escalate to the risk committee with a temporary compensating controls proposal
C. Accept the delay since the business unit owner is the risk owner
D. Commission a follow-up penetration test to validate exploit feasibility
Come back for the answer tomorrow, orstudy more now!
4
28 comments
Vincent Primiani
7
CISSP Practice Question (Domain 6: Security Assessment and Testing)
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by