Cisco CCNP Security Core (SCOR) 350-701Security ConceptsEasy

A financial institution is required to undergo an annual external audit of its information systems to ensure compliance with industry regulations and standards. This audit specifically aims to verify the effectiveness of implemented security controls and identify any significant deficiencies. Which type of security assessment is being performed?

  1. ARisk Assessment
  2. BSecurity Audit
  3. CVulnerability Scan
  4. DPenetration Test
Show answer & explanation

Correct answer: B. Security Audit

A security audit is a systematic evaluation of an organization's security posture against established criteria, often for compliance purposes. The scenario explicitly mentions an 'annual external audit' to 'verify the effectiveness of implemented security controls' and 'identify deficiencies' for 'compliance with industry regulations,' which perfectly matches the definition of a security audit.

Why the other options are wrong

  • A. A risk assessment identifies and analyzes risks, but the scenario describes verifying existing controls and compliance, which is an audit function.
  • C. A vulnerability scan identifies known weaknesses but doesn't usually verify control effectiveness or compliance comprehensively.
  • D. A penetration test actively exploits vulnerabilities to test defenses, which is more aggressive than the described audit scope.

Security Audit

A systematic, independent examination of an organization's security posture to determine the extent to which security controls are adequate and effective.

  • Often conducted by external parties.
  • Verifies compliance with policies, regulations, and standards.
  • Identifies control weaknesses and areas for improvement.

Memory trick: Assessments 'ASSESS' what's 'SECURE' or 'NOT' in the 'SYSTEM'.

More Security Concepts questions