|
|
เตรียมตัวสอบ CISA
Area 02 : Question 57 ( C1 - 57 ) |
|
3
4
|
Question : Which of the following would provide the LEAST justification for an organization's investment in a security infrastructure ?
A) |
Risk analysis of internal/external threats |
|
B) |
A white paper report on Internet attacks, companies attacked, and damage inflicted |
|
C) |
A penetration test of the organization's network demonstrates that the threat from intruders is high |
|
D) |
Reports generated internally from use of high-profile network tools |
Question |
|
( ) |
|
|
Choice : A |
|
Choice : B |
|
Choice : C |
|
Choice : D |
The Correct Answer is :
B. A white paper report on Internet attacks, companies attacked, and damage inflicted
Explanation :
Occurrences of security attacks from other organizations would have the least impact on a decision made by management to establish a security infrastructure ( versus analysis and/or demonstrated threats directly affecting the organization ).
A risk analysis would enable an organization to assess severity of risks posed to information assets by both internal and external perpetrators.
A penetration test showing the ability to compromise the organization's network and reports generated internally from use of high profile network tools would also sufficiently justify investment in a network security infrastructure.
|