Skip to content

FRM Part II · FRM Exam Part II · Cyber-resilience: Range of Practices

A bank runs penetration tests and a continuous vulnerability scanning programme. Management says that because the last annual penetration test found no critical issues, the bank can reduce monitoring spending. Which response best reflects sound cyber-resilience practice?

Management should be told that a clean penetration test is only a point-in-time result. Threats, software and configurations keep changing, so continuous monitoring and detection remain necessary. Testing and scanning complement each other, and neither justifies cutting ongoing monitoring spending.

  1. AAgree, because a clean test shows controls are permanently effective
  2. BDisagree, because testing gives a point-in-time view and threats and configurations change, so ongoing detection and monitoring remain necessaryCorrect
  3. CAgree, provided the test was performed by an internal team
  4. DDisagree, because penetration tests should be replaced entirely by vulnerability scans

Explanation

A penetration test is a snapshot limited by scope and time. New vulnerabilities, configuration changes and evolving attackers mean continuous monitoring is still needed. Replacing tests with scans is also wrong because the two are complementary.

Did you get it right without looking?

One question tells you little. A timed set on Cyber-resilience: Range of Practices shows your real accuracy, how long you take and where you lose marks.

More Cyber-resilience: Range of Practices questions