CAF-3 · Chapter 17 · Question 5 of 15
The IT department regularly uses automated tools like Nessus and OpenVAS to scan the corporate network. What is the primary purpose of these specific tools in the risk management cycle?
Test yourself: pick an answer
Reveal answer & explanation
Correct answer: C) To identify security vulnerabilities, such as missing patches or misconfigured firewalls
Explanation
Nessus and OpenVAS are automated risk and vulnerability scanners used during the Risk Identification phase to detect weaknesses like misconfigured firewalls or out-of-date security patches before attackers can exploit them
More Best Practices & Implementation Strategies MCQs
- Q7An organization creates a cross-functional risk management committee with members from Finance, IT, and HR who are located in different…
- Q8A company's network detects that one of its primary web servers is malfunctioning and automatically reroutes all incoming customer traffic…
- Q9Following a minor data breach, the IT security team uses specialized software to trace the attacker's exact entry point and the specific…
- Q10What is the primary benefit of continuously collecting data from past risk incidents and feeding it into an organization's ICT systems?
- Q11To ensure employees truly understand the theoretical risk management policies, the IT department periodically sends out fake, deceptive…
