CertKeen

CompTIA Security+ (SY0-701) · Free practice question 10 of 12

Gap analysis against a framework

Kinross Health wants to compare its current security controls with the requirements of a recognized framework to see which controls are missing before an audit. What is this assessment called?

  1. A.Penetration test
  2. B.Gap analysis
  3. C.Root cause analysis
  4. D.Business impact analysis
Show answer and explanation

Correct answer: B. Gap analysis

Why: A gap analysis compares the current state of controls with a target state, such as a framework's requirements, and identifies what is missing. A penetration test tries to exploit weaknesses, and a business impact analysis estimates the operational and financial effects of an outage. Root cause analysis explains why a specific incident occurred.

More free CompTIA Security+ (SY0-701) questions