正解:B
While audits and assessments provide periodic insights, the best time to verify that security mechanisms meet control objectives is continuously-through monitoring and automation.
Continuous monitoring allows the organization to detect misconfigurations, anomalies, or control failures in real-time, significantly improving response capabilities. Modern environments, especially in production systems, require real-time feedback loops to maintain compliance and effectiveness due to rapidly evolving threats and configuration changes.
"Continuous monitoring provides assurance that controls are operating effectively in real time, enabling timely corrective actions."
- CISM Review Manual 15th Edition, Chapter 4: Incident Management, Section: Control Monitoring*