medium
Single Answer
0What process reviews control objectives for an organization, system, or service to determine if controls do not meet the control objectives?
Answer Options
A
A penetration test
B
A gap analysis
C
A Boolean analysis
D
A risk analysis
Correct Answer: B
Explanation
A gap analysis is used to determine whether controls meet control objectives for a service, an organization, or a system. Penetration tests simulate an attacker trying to gain access or breach systems and other controls. Boolean analysis is not a security term, and risk analysis is done as part of risk assessment.