Conducting vulnerability assessmentsonly once per year, right before an audit,creates a false sense of securityandleaves systems exposedbetween assessments.
Annual Testing Before Audit (Correct Answer – A)
Risksundetected vulnerabilitiesfor extended periods.
Example:A company only tests security before acompliance audit, allowingzero-day threatsto persist for months.
Internal Team Conducting Assessments (Incorrect – B)
Not ideal, butregular assessmentsare more critical.
Focusing on Critical Systems (Incorrect – C)
Not perfect, butbetter than no testing at all.
Using Open-Source Tools (Incorrect – D)
Open-source toolscan be effective ifproperly configured.
[References:, ISACA CISA Review Manual, NIST 800-115 (Technical Guide to Security Testing), , , , , , ]