QuestionQ11

Security Testing as Part of an Information Security Management System (ISMS)

Which of the following accurately describes the role of security testing in the context of security audits?

  • A Reviewing the adherence to GDPR policies by examining documented procedures for handling user consent and verifying logs for compliance with data access restrictions.
  • B Validating that encryption protocols in an online payment gateway are properly implemented and effective in securing customer credit card information during transactions.
  • C Evaluating the cloud service provider’s recovery plan by reviewing documented backup policies and procedures and verifying records of regular backup tests.
  • D Checking the effectiveness of installed firewall rules in a corporate network by reviewing logs to ensure that unauthorized access attempts were blocked according to the security policy.
Explanation

Security testing validates that technical security controls are correctly implemented and effective. Assessing encryption protocols in an online payment gateway verifies that customer credit-card data is protected during transactions.

Community Discussion

No comments yet. Be the first to start the discussion!