Most Important Consideration for Vulnerability Scanning Critical Infrastructure?

Vulnerability Management
Answer Correct answer: D — Ensure vulnerability scans do not degrade system performance to maintain continuous operation of critical IT infrastructure.

Which of the following is the MOST important consideration when establishing vulnerability scanning on critical IT infrastructure?

  1. The scanning will be cost-effective.
  2. The scanning will be performed during non-peak hours.
  3. The scanning will be followed by penetration testing.
  4. The scanning will not degrade system performance. Correct Answer

Community Votes

D
80%
B
20%

80% of anonymous learners picked answer D. Votes are pick records left by other test-takers — they are not the verified answer.

Community Insight

This question tests your ability to prioritize business continuity over technical convenience, with the common trap being choosing off-peak scheduling instead of addressing direct performance impact.

When implementing vulnerability scans on critical infrastructure, preventing operational disruption is the top priority. Community consensus confirms that maintaining system performance outweighs scheduling or cost factors.

Option B is frequently chosen because it seems practical, but it fails to address the fundamental requirement that scans must never degrade critical system performance regardless of timing.

Community Discussion (3 comments)

choboanon 👍 1 Selected: D
D is correct. First determine if it's an issue, not jump straight to off-hours scanning
PurpleParrot 👍 3 Selected: D
Option D is the correct answer
Swallows 👍 1 Selected: B
Vulnerability scanning of critical infrastructure must be performed without affecting the normal operation of the system. Scanning during peak hours may result in insufficient network bandwidth and resources, which may affect system performance. Therefore, it is recommended to select off-peak hours for scanning.

Comments & Corrections

No comments yet — spotted an error or have a note? Share it below.

Log in to comment, report an error, or add a note about this question.

Submitted for moderation before publishing. Keep it helpful and respectful.

Expert Analysis

Why the Answer Is Correct

Vulnerability scanners consume significant CPU cycles and network bandwidth, which directly threatens availability. ISACA’s CISA framework mandates that security assessments must never compromise the continuous operation of mission-critical assets. Therefore, guaranteeing zero performance degradation is the primary control objective before any other implementation step.

Why the Other Options Are Wrong

Cost-effectiveness (A) is a secondary administrative concern that cannot override operational risk. Scheduling during non-peak hours (B) is merely a tactical workaround that does not eliminate the inherent resource consumption of scanning tools. Penetration testing (C) is a subsequent validation phase that relies on established scanning baselines rather than dictating initial deployment criteria.

Community Comment Notes

Candidate discussions consistently validate D as the optimal choice for enterprise environments. Comment [1] and [2] explicitly confirm that preserving system integrity takes precedence over logistical convenience. While comment [3] suggests off-peak execution, it ultimately acknowledges that performance preservation remains the underlying rationale for that recommendation.

Official Reference

Exam Strategy

When answering CISA questions involving critical infrastructure, always prioritize business continuity and operational stability over technical optimizations or cost savings. Look for options that prevent service disruption before considering scheduling or budget constraints.

Frequently Asked Questions

Why isn't off-peak scanning the best answer for critical infrastructure?

Off-peak scheduling is a mitigation tactic, not the primary control. Even during low-traffic windows, aggressive scans can still crash legacy systems or spike latency, making performance preservation the foundational requirement.

Does cost-effectiveness matter more than system stability during vulnerability assessments?

No. ISACA prioritizes business continuity and risk mitigation over budget constraints. Financial efficiency cannot justify risking operational downtime on critical assets.

Related Analysis

Practice All CISA Questions

Access 400 questions with complete answers and detailed explanations.

View Full CISA Practice Test →

← Back to CISA Study Guide