exam questions

Exam CISA All Questions

View all questions & answers for the CISA exam

Exam CISA topic 1 question 1079 discussion

Actual exam question from Isaca's CISA
Question #: 1079
Topic #: 1
[All CISA Questions]

A web application is developed in-house by an organization. Which of the following would provide the BEST evidence to an IS auditor that the application is secure from external attack?

  • A. Database application monitoring logs
  • B. Code review by a third party
  • C. Penetration test results
  • D. Web application firewall implementation
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
FAGFUR
4 months ago
Selected Answer: C
The best evidence to an IS auditor that a web application is secure from external attack is penetration test results. Penetration testing involves simulating real-world attacks on the application to identify vulnerabilities and weaknesses. The results of a penetration test provide concrete evidence of the security posture of the web application and highlight areas that may need improvement.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago