An organization is required to provide assurance that its controls are properly designed and operating effectively. Which of the following reports will best achieve this objective?
正解:C
The correct answer is C. Independent audit.
An independent audit provides objective assurance that security controls are properly designed, implemented, and operating effectively. Audits are commonly used to validate compliance, governance, risk management, and control effectiveness.
This aligns with CompTIA Security+ SY0-701 topics involving audits, assessments, governance, compliance, and third-party assurance.
Why the other options are incorrect:
A). Red teaming
Red teaming simulates real-world adversary behavior to test detection and response capabilities. It does not provide the same formal assurance over control design and operating effectiveness.
B). Penetration testing
Penetration testing identifies exploitable vulnerabilities, but it does not comprehensively verify that all controls are properly designed and operating effectively.
D). Vulnerability assessment
A vulnerability assessment identifies and prioritizes weaknesses, but it does not provide formal assurance of control design and operating effectiveness.
Therefore, the best answer is independent audit.