Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 916 discussion

Actual exam question from Isaca's CISA
Question #: 916
Topic #: 1
[All CISA Questions]

Which of the following is the BEST report for an IS auditor to reference when tasked with reviewing the security of code written for a newly developed website?

  • A. Black box testing report
  • B. Static software composition analysis
  • C. Penetration test report
  • D. Web application vulnerability report
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
3008
Highly Voted 1 year, 6 months ago
Selected Answer: B
b is answer
upvoted 6 times
...
Pakawat
Highly Voted 1 year, 5 months ago
Selected Answer: D
D: Refer to OWASP report is the best report.
upvoted 5 times
...
a84n
Most Recent 6 months, 2 weeks ago
Selected Answer: C
Q: BEST REPORT for reviewing the SECURITY OF CODE written for a newly developed website? Answer: C A static software composition analysis (SCA) report primarily focuses on identifying vulnerabilities in third-party libraries and components used in the software. While this type of analysis is valuable for identifying potential security issues arising from dependencies on external code, it may not provide comprehensive coverage of security issues specific to the custom code written for the website. Penetration testing, on the other hand, involves actively probing and testing the website's code, configuration, and overall security posture by simulating real-world attack scenarios. This type of testing is more likely to uncover vulnerabilities specific to the custom code and implementation of the website, making the penetration test report a better choice for reviewing the security of the website's code.
upvoted 1 times
...
Swallows
8 months ago
Selected Answer: B
By using static analysis tools to analyze source code, you can identify problems early in each process of a development project, allowing for quick fixes and reducing the cost of fixing bugs throughout the project.
upvoted 2 times
Swallows
5 months, 3 weeks ago
While web application vulnerability reports (Option D) are valuable for assessing the security of a website, they primarily focus on testing the website in its deployed state and identifying vulnerabilities from an external perspective. On the other hand, static software composition analysis (Option B) specifically examines the codebase itself, making it the BEST choice for reviewing the security of code written for a newly developed website.
upvoted 1 times
choboanon
3 weeks ago
D is more comprehensive and shows you the state of the site in more real-world scenarios that could be overlooked in a static code analysis. Answer is D
upvoted 1 times
...
...
...
SuperMax
1 year, 1 month ago
Selected Answer: C
C. Penetration test report Penetration testing involves actively probing a system to identify vulnerabilities and weaknesses, including those within the code of a web application. This type of testing simulates real-world attacks and provides valuable insights into potential security risks. A penetration test report would detail the findings, vulnerabilities discovered, and recommendations for remediation, making it an essential reference for an IS auditor assessing the security of a newly developed website. While the other options (A. Black box testing report, B. Static software composition analysis, and D. Web application vulnerability report) may also provide useful information, a penetration test report specifically focuses on assessing the security of the application in a real-world scenario, which is highly relevant for an IS auditor's security review.
upvoted 1 times
3008
11 months, 2 weeks ago
Nonsense....
upvoted 1 times
...
...
saado9
1 year, 6 months ago
Static software composition analysis
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...