正解:B
The finding that should be of greatest concern to an IS auditor assessing the effectiveness of an organization' s vulnerability scanning program is that results are not reported to individuals with authority to ensure resolution. This indicates a lack of accountability and communication for vulnerability management, which may result in unresolved or delayed remediation of identified vulnerabilities. This may expose the organization to increased risk of cyberattacks or breaches. The other findings are also concerning, but not as much as this one, because they may affect the completeness, accuracy or timeliness of the vulnerability scanning process, but not necessarily its effectiveness. References:
* ISACA, CISA Review Manual, 27th Edition, chapter 4, section 4.41
* ISACA, COBIT 2019 Framework: Introduction and Methodology, section 3.2