Cisco CyberOps Associate (CBROPS) 200-201Security Policies and ProceduresMedium

During a routine security audit, it is discovered that several employees are sharing login credentials for a critical production server, despite a clear organizational policy prohibiting this practice. The audit report identifies this as a significant vulnerability. Which type of security assessment would be most appropriate to systematically identify the extent of such policy violations and the potential impact across the organization?

  1. ARed team exercise
  2. BVulnerability scan
  3. CCompliance audit
  4. DPenetration test
Show answer & explanation

Correct answer: C. Compliance audit

A compliance audit is specifically designed to assess an organization's adherence to internal policies, industry standards, and regulatory requirements, making it the most appropriate assessment for identifying policy violations.

Why the other options are wrong

  • A. Red team exercises simulate real-world attacks to test defenses, not primarily to check internal policy compliance.
  • B. Vulnerability scans identify technical weaknesses, not policy violations by users.
  • D. Penetration tests simulate attacks to exploit vulnerabilities, not primarily to audit policy adherence.

Compliance Audit

A systematic review to determine whether an organization is following external regulations, internal policies, and industry standards.

  • Focuses on adherence to established rules and guidelines.
  • Can involve reviewing documentation, interviewing personnel, and testing controls.
  • Aims to identify gaps in compliance and areas for improvement.

Memory trick: Assessments VASTly improve security: Vulnerability, Audit, Simulation, Test.

More Security Policies and Procedures questions