exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 303 discussion

Actual exam question from ISC's CCSP
Question #: 303
Topic #: 1
[All CCSP Questions]

During the course of an audit, which of the following would NOT be an input into the control requirements used as part of a gap analysis.

  • A. Contractual requirements
  • B. Regulations
  • C. Vendor recommendations
  • D. Corporate policy
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️
Vendor recommendations would not be pertinent to the gap analysis after an audit. Although vendor recommendations will typically play a role in the development of corporate policies or contractual requirements, they are not required. Regulations, corporate policy, and contractual requirements all determine the expected or mandated controls in place on a system.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
akg001
5 months ago
Selected Answer: C
C. Vendor recommendations
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago