exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 364 discussion

Actual exam question from ISC's CISSP
Question #: 364
Topic #: 1
[All CISSP Questions]

Which of the following should exist in order to perform a security audit?

  • A. Neutrality of the auditor
  • B. Industry framework to audit against
  • C. External (third-party) auditor
  • D. Internal certified auditor
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Jamati
Highly Voted 3 years ago
Selected Answer: B
Is the auditor using COBIT, ISO 27001, or ISO 27002? The MOST important thing is what governance and compliance standards they're testing against, not whether they're biased or neutral. Every human being has a built-in bias.
upvoted 13 times
jackdryan
2 years, 6 months ago
B is correct
upvoted 1 times
...
...
M_S_L
Most Recent 1 month, 3 weeks ago
Selected Answer: B
🔹 Option Analysis A. Neutrality of the auditor Neutrality/independence is very important for audit credibility. But even without neutrality, an audit can still be performed (though not effective). ❌ Not the primary requirement. B. Industry framework to audit against ✅ For an audit to exist, there must be a baseline/criteria to measure against (e.g., ISO 27001, NIST, PCI DSS, internal policy). Without a standard/framework, there’s nothing to “audit against.” ✅ Correct. C. External (third-party) auditor Some audits require third parties (e.g., PCI QSA), but many are internal audits. Not always necessary. ❌ Too specific. D. Internal certified auditor Certifications (CISA, etc.) add credibility, but are not a requirement for conducting an audit. ❌ Not mandatory. 👉 Memory Tip: Audit = measure against a baseline. No baseline = just a review, not an audit.
upvoted 1 times
...
ATT5832
4 months, 1 week ago
Selected Answer: A
Answer A. Not B because you might be auditing against internal customer-specific requirements.
upvoted 1 times
...
Mr_Zaw
4 months, 3 weeks ago
Selected Answer: A
Both the neutrality of the auditor and having an industry framework to audit against are crucial, but neutrality of the auditor is generally considered more fundamental. While a framework provides a standard for assessment, the auditor's impartiality is essential for ensuring the audit is fair, objective, and free from bias. Without neutrality, even a robust framework can be compromised by subjective interpretations or skewed results.
upvoted 1 times
...
BigITGuy
8 months ago
Selected Answer: A
Industry framework is useful but not required — audits can also be performed against internal policies or client-specific requirements.
upvoted 2 times
Trap_D0_r
3 days, 3 hours ago
God you just froth stupid in every direction. lol, what? Internal audits happen ALL the time. Typically before an external audit, the department will run a self-audit to prepare. You're allowed to audit yourself, as long as you have a framework to audit against. "A" doesn't even make any sense. The question isn't specifically about 3rd party audits, it's "what do you need to have before you audit?" the answer is "a framework to run your audit against, very obviously, you bigstupiditguy dummy.
upvoted 1 times
...
6dc1fe1
5 months, 2 weeks ago
Not just audit, it says "security audit"
upvoted 1 times
...
...
Dtony66
10 months, 1 week ago
Selected Answer: A
Should the auditor be impartial, the findings would be meaningless. The other answers can be optional. Do not agree with this one.
upvoted 2 times
...
deeden
1 year, 3 months ago
Selected Answer: A
While having an industry framework (such as ISO 27001, NIST, or CIS Controls) to audit against is very important, it is not a prerequisite for performing a security audit. Audits can be conducted based on internal policies, procedures, or other criteria, even if a formal industry framework is not being used. Neutrality of the auditor is crucial for ensuring that the audit is impartial, objective, and free from bias. The auditor must be independent of the entity or the specific operations being audited to provide an honest assessment of the security posture. This neutrality ensures that the findings and recommendations are based on actual evidence rather than being influenced by internal pressures or conflicts of interest.
upvoted 2 times
Trap_D0_r
3 days, 3 hours ago
and again, and INTERNAL audit will not (and generally cannot) be conducted in a neutral way. However, they are conducted all the time.
upvoted 1 times
...
6dc1fe1
5 months, 2 weeks ago
Again, It says "Security Audit" meaning it's a standard audit, meaning it requires a standard.
upvoted 1 times
...
...
klarak
1 year, 6 months ago
Selected Answer: B
Terrible question, it should say "MUST" exist. Any of the 4 could be right depending on the situation. If you're doing self-assessment for the SPRS system, for example, the assessor doesn't have to be 3rd party or neutral, they just have to be truthful.
upvoted 3 times
...
GuardianAngel
1 year, 9 months ago
A. Neutrality of the auditor Definition of security audit from the ISC2 study guide mentions bias: security audits Evaluations performed with the purpose of demonstrating the effectiveness of controls to a third party. Security audits use many of the same techniques followed during security assessments but must be performed by independent auditors. The staff members who design, implement, and monitor controls for an organization have an inherent conflict of interest when evaluating the effectiveness of those controls.
upvoted 1 times
...
gjimenezf
1 year, 10 months ago
Selected Answer: B
What should exist to PERFORM the audit? B, A framework to audit against What is important to prevent bias in the audit RESULT? A, Neutral auditor Is asking what should exist to begin the audit not considering what would be the results.
upvoted 2 times
...
629f731
1 year, 10 months ago
Selected Answer: C
C. In many cases, an external (third-party) auditor is preferred because they typically have fewer biases or conflicts of interest compared to an internal auditor. Auditor independence ensures that the evaluation is objective and free of internal influences that could affect the impartiality of the audit results. Therefore, the impartiality of the auditor is arguably more crucial, and the choice of an external auditor often contributes to that impartiality.
upvoted 1 times
...
GPrep
1 year, 10 months ago
Selected Answer: A
I'm sticking with A for two reasons: 1 - There are three types of audit strategies – Internal, External, and Third-party. Internal audits should be closely aligned to the organization, the external strategy needs to ensure procedures/compliance are being followed with regular checks and complement the internal strategy. The third-party strategy is an objective, neutral approach that reviews the overall strategy for auditing the organization’s environment, methods of testing, and can also ensure that both internal and external audits are following defined policies and procedures.- https://resources.infosecinstitute.com/certifications/cissp/cissp-domain-6-refresh-security-assessment-and-testing/ 2. Audits only have to be aligned to an industry framework for certification. Audits can be performed for other reasons with a varied scope tailored to the specific organization.
upvoted 3 times
...
Soleandheel
1 year, 11 months ago
A and B are important aspects of performing a security audit, but A is the better answer choice because it directly addresses the impartiality and objectivity of the auditor, which is a fundamental principle of auditing. A. Neutrality of the auditor: Neutrality refers to the auditor's impartiality and lack of bias in conducting the audit. It ensures that the auditor's judgment and findings are not influenced by personal or financial interests. Neutrality is a core principle of auditing to maintain the credibility and integrity of the audit process.
upvoted 2 times
Soleandheel
1 year, 11 months ago
Neutrality is a core principle of auditing to maintain the credibility and integrity of the audit process.
upvoted 1 times
...
...
oudmaster
2 years, 11 months ago
Selected Answer: B
"Neutrality of the auditor" is something qualitative and cannot be trusted. What we care is the result of the audit, and it has to be based on standards.
upvoted 2 times
...
rajkamal0
2 years, 11 months ago
Selected Answer: B
After assessing all the information posted here, I am going with B.
upvoted 2 times
...
Coolwater
3 years, 1 month ago
Selected answer is correct - Points in the question " Should Exist, " "Security Audit ". We can't measure the neutrality of an auditor regardless if he is internal or external . Security audi must conduct against a framework such as ISO27001 etc.. Otherwise how we can do an audit properly?
upvoted 1 times
...
WiDeBarulho
3 years, 1 month ago
Selected Answer: B
Regardless of how neutral the auditor is, you won't have reliable results unless you have an defined industry framework to audit against. Given answer is correct.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...