Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 67 discussion

Actual exam question from ISC's CISSP
Question #: 67
Topic #: 1
[All CISSP Questions]

Which section of the assessment report addresses separate vulnerabilities, weaknesses, and gaps?

  • A. Findings definition section
  • B. Risk review section
  • C. Executive summary with full details
  • D. Key findings section
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
AMANSUNAR
1 year ago
Selected Answer: D
The key findings section of an assessment report provides a detailed breakdown of identified vulnerabilities, weaknesses, and gaps. It offers a comprehensive overview of the security issues discovered during the assessment.
upvoted 1 times
...
InclusiveSTEAM
1 year, 1 month ago
The answer is D The section of an assessment report that addresses individual vulnerabilities, weaknesses, and gaps is the key findings section. The key findings provides the detailed technical breakdown of the specific issues uncovered during testing/examination. It outlines and describes each finding. The executive summary and risk review sections provide higher-level overview and analysis. The findings definition section explains risk scoring but doesn't cover the vulnerabilities themselves.
upvoted 3 times
...
VVine
1 year, 2 months ago
Selected Answer: D
Key findings provides detailed info
upvoted 2 times
...
Bach1968
1 year, 4 months ago
Selected Answer: D
The section of the assessment report that typically addresses separate vulnerabilities, weaknesses, and gaps is the "Findings" or "Key Findings" section. Option D, "Key findings section," is the most appropriate choice. In this section, the report typically presents a detailed analysis of the identified vulnerabilities, weaknesses, and gaps discovered during the assessment process. It provides specific information about each finding, including the nature of the issue, its impact on the system or organization, and recommendations for remediation or mitigation. This section helps the recipient of the report understand the specific areas of concern that need to be addressed to improve the security posture.
upvoted 2 times
...
Moose01
1 year, 6 months ago
D. is the correct one (Key findings) - Key means most important and what audit was intended for to begin with. This section of the report establishes what the audit was about, why the audit risk areas mattered to management, and what the team included in the audit. Next, the report details the issues that were found in the results section.
upvoted 1 times
...
BennyMao
1 year, 6 months ago
Selected Answer: D
The key findings section is correct.
upvoted 2 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 2 times
...
...
Tygrond87
1 year, 6 months ago
Selected Answer: A
The section of the assessment report that addresses separate vulnerabilities, weaknesses, and gaps is the "Findings definition section". This section is where the specific vulnerabilities, weaknesses, or gaps that were discovered during the assessment are documented in detail. It often includes a description of the issue, its potential impact, and recommendations for remediation. The findings definition section is a critical component of the assessment report as it provides a detailed breakdown of the issues that need to be addressed to improve the security posture of the organization.
upvoted 4 times
Mike4649
1 year, 3 months ago
Agree with A
upvoted 1 times
...
...
Dee83
1 year, 10 months ago
A. Findings definition section addresses separate vulnerabilities, weaknesses, and gaps. This section of the report typically includes a detailed description of the vulnerabilities, weaknesses, and gaps identified during the assessment, along with their potential impact on the organization's security posture. This section may also include recommendations for mitigating or remediating the identified issues, to help the organization improve its security.
upvoted 3 times
...
pingundas
2 years ago
Using this as an example, the given answer is correct: https://www.ndlegis.gov/files/committees/67-2021/23_5011_3000appendixb.pdf
upvoted 3 times
Jamati
2 years ago
According to this document the answer is Executive Summary
upvoted 1 times
SSimko
10 months ago
It is D, it is a sub section of executive summary... it is the "most correct" answer out of the 4.
upvoted 1 times
...
...
...
rootic
2 years ago
Selected Answer: B
Agree with B.
upvoted 1 times
...
franbarpro
2 years, 1 month ago
Def. "B"
upvoted 1 times
...
sphenixfire
2 years, 1 month ago
Same, b
upvoted 1 times
...
Joey456
2 years, 1 month ago
B - https://www.eccouncil.org/cybersecurity-exchange/ethical-hacking/how-to-write-vulnerability-assessment-report/#:~:text=Creating%20a%20vulnerability%20assessment%20report,automated%20and%20manual%20testing%20tools.
upvoted 3 times
...
CharlesL
2 years, 1 month ago
Selected Answer: B
Definitely is B
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...