The CA Hub

CAF-3 · Chapter 17 · Question 5 of 15

The IT department regularly uses automated tools like Nessus and OpenVAS to scan the corporate network. What is the primary purpose of these specific tools in the risk management cycle?

Test yourself: pick an answer

Reveal answer & explanation

Correct answer: C) To identify security vulnerabilities, such as missing patches or misconfigured firewalls

Explanation

Nessus and OpenVAS are automated risk and vulnerability scanners used during the Risk Identification phase to detect weaknesses like misconfigured firewalls or out-of-date security patches before attackers can exploit them

All 15 questions in Chapter 17Best Practices & Implementation Strategies MCQs with answers

More Best Practices & Implementation Strategies MCQs

Sponsored slot availableRun a CA academy or hiring firm? Put your name in front of students preparing for this exam.Advertise →