medium
Single Answer
0

What process reviews control objectives for an organization, system, or service to determine if controls do not meet the control objectives?

Answer Options

A

A penetration test

B

A gap analysis

C

A Boolean analysis

D

A risk analysis

Correct Answer: B

Explanation

A gap analysis is used to determine whether controls meet control objectives for a service, an organization, or a system. Penetration tests simulate an attacker trying to gain access or breach systems and other controls. Boolean analysis is not a security term, and risk analysis is done as part of risk assessment.