A cybersecurity audit firm has completed a penetration test of an organization’s web application. The final report contains two findings that indicate the presence of two critical vulnerabilities. The organization disputes the findings because of the presence of compensating controls outside of the web application interface. How should the audit proceed?

🎲 Try a Random Question  |  Total Questions in Quiz: 63  |  🧠 Study this quiz with Flashcards
This question is part of a full practice quiz:
CISA Domain 1: Information Systems Auditing Process — practice the complete quiz, review flashcards, or try a random question.


A cybersecurity audit firm has completed a penetration test of an organization’s web application. The final report contains two findings that indicate the presence of two critical vulnerabilities. The organization disputes the findings because of the presence of compensating controls outside of the web application interface. How should the audit proceed?