- Home
- All questions
- Question 365
CISSP study material · question 365 of 500
An assessment programme has phases for planning and execution but stops when the findings list is produced. Which three activities does SP 800-115 place in the post-execution phase? Choose three.
Show the answer
Answer: D. Analysing the identified vulnerabilities to determine root causes.
C. Establishing mitigation recommendations.
B. Developing the final report.
The post-execution phase focuses on analysing vulnerabilities to determine root causes, establishing mitigation recommendations and developing the final report. Rules of engagement belong to planning.
Source: NIST SP 800-115 (NIST) — SP 800-115 > 2.1 Information Security Assessment Methodology