侵入テストで、ファイアウォールが正しく構成されていないためにセキュリティが危険にさらされていることが判明した場合、情報セキュリティ マネージャーが取るべき最善の行動はどれですか。
正解:A
A penetration test is a proactive way to identify and remediate security vulnerabilities in a network. When a penetration test reveals a security exposure due to a firewall that is not configured correctly, the information security manager's best course of action is to ensure a plan with milestones is developed to address the issue.
This plan should include the root cause analysis, the corrective actions, the responsible parties, the deadlines, and the verification methods. This way, the information security manager can ensure that the security exposure is resolved in a timely and effective manner, and that the firewall configuration is aligned with the security policy and the business objectives.
References