Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISM All Questions

View all questions & answers for the CISM exam

Exam CISM topic 1 question 1166 discussion

Actual exam question from Isaca's CISM
Question #: 1166
Topic #: 1
[All CISM Questions]

When engaging an external party to perform a penetration test, it is MOST important to:

  • A. provide an updated asset inventory.
  • B. notify employees of the testing.
  • C. define the project scope.
  • D. provide network documentation.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Booict
4 months ago
C- Clearly outline the objectives, systems, and boundaries of the penetration test. Helps the external party focus on relevant areas and avoid unintended consequences. Ensures alignment with organizational goals.
upvoted 2 times
...
Dice974
5 months, 2 weeks ago
Selected Answer: C
Have to define the scope so they are testing your public IPs and not someone else's IPs. Also do you want risky test that may take down a system etc.
upvoted 2 times
...
shootnot
6 months ago
Selected Answer: C
The Q doesn't mention whitebox or blackbox testing therefore providing assent inventory is not correct. even if it was specified, just providing inventory is not enough and would be covered under scope if necessary.
upvoted 1 times
...
helg420
6 months ago
Selected Answer: C
C: A clearly defined scope
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...