CompTIA Security+ (SY0-701) · Free practice question 10 of 12
Gap analysis against a framework
Kinross Health wants to compare its current security controls with the requirements of a recognized framework to see which controls are missing before an audit. What is this assessment called?
- A.Penetration test
- B.Gap analysis
- C.Root cause analysis
- D.Business impact analysis
Show answer and explanation
Correct answer: B. Gap analysis
Why: A gap analysis compares the current state of controls with a target state, such as a framework's requirements, and identifies what is missing. A penetration test tries to exploit weaknesses, and a business impact analysis estimates the operational and financial effects of an outage. Root cause analysis explains why a specific incident occurred.
More free CompTIA Security+ (SY0-701) questions
- Access control vestibule stops tailgating
- Trusted Platform Module characteristics
- Blockchain open public ledger integrity
- Virtual machine escape vulnerability
- Jump server for administrative access
- OAuth delegated authorization without passwords
- Non-disclosure agreement for consultants
- Passive reconnaissance from public sources
- Mean time between failures reliability
- Offline backups for ransomware recovery
- Steganography hiding data in images