Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 627 discussion

Actual exam question from Isaca's CISA
Question #: 627
Topic #: 1
[All CISA Questions]

An external IS auditor has been engaged to determine the organization's cybersecurity posture. Which of the following is MOST useful for this purpose?

  • A. Capability maturity assessment
  • B. Compliance reports
  • C. Control self-assessment (CSA)
  • D. Industry benchmark report
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
PurpleParrot
2 months, 4 weeks ago
Selected Answer: A
The answer is A. Compliance reports show whether the organization meets specific regulatory requirements and standards. While they are important for ensuring legal and regulatory compliance, they may not provide a full picture of the organization’s overall cybersecurity posture and effectiveness.
upvoted 1 times
...
Swallows
4 months ago
Selected Answer: B
I will change my answer to B: The Capability Maturity Assessment (Option A) evaluates the degree to which an organization has matured its IT and cybersecurity processes. This assessment is important from the perspective of effective management and continuous improvement of processes, but it does not directly provide details on compliance with regulatory requirements or the implementation of security controls. Therefore, the most effective way to determine the cybersecurity posture is to have an external IS auditor review the compliance report.
upvoted 1 times
...
Swallows
6 months ago
Selected Answer: A
A capability maturity assessment evaluates an organization's cybersecurity practices and processes against industry-recognized frameworks. It provides insights into the organization's maturity level across various cybersecurity domains, including governance, risk management, access controls, incident response, and security operations.
upvoted 1 times
...
Sibsankar
7 months, 2 weeks ago
Capability maturity assessment (CMM): CMMs assess the maturity of specific processes, like software development, which might be helpful but don't provide a complete picture of cybersecurity posture. May be C:
upvoted 1 times
...
Yejide03
8 months ago
A. Capability maturity assessment. Capability maturity assessment involves evaluating the organization's cybersecurity capabilities across various domains, such as governance, risk management, compliance, security operations, and incident response. This assessment provides a comprehensive understanding of the organization's cybersecurity maturity level, strengths, weaknesses, and areas for improvement. It helps the auditor gauge the organization's ability to effectively address cybersecurity risks and threats based on its current capabilities. Therefore, a capability maturity assessment would be the most useful tool for the external IS auditor to assess the organization's cybersecurity posture.
upvoted 1 times
...
saado9
1 year, 6 months ago
A. Capability maturity assessment
upvoted 4 times
Yejide03
9 months ago
B. Compliance reports
upvoted 1 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...