SY0-701 Question 15
Single answerGap analysisA healthcare company is preparing for an external security assessment after expanding into a new cloud-hosted patient portal. Leadership has asked the security manager to determine where current security controls do not meet the organization's required baseline for protecting sensitive data and complying with internal policy. The manager has collected the current-state control inventory, the target security baseline, and relevant regulatory requirements. Which action should the manager perform NEXT to support a gap analysis?
- A
Compare the current controls against the desired baseline and document any missing or insufficient controls
- B
Immediately begin remediating all known weaknesses in the cloud environment
- C
Conduct a penetration test to exploit vulnerabilities before reviewing the baseline
- D
Purchase a new security framework tool to automate future audits
Show answer and explanation
Correct answer: A
Explanation
Gap analysis in security is used to identify differences between the organization's current security posture and a required or desired state, such as an internal standard, regulatory obligation, or recognized framework baseline. In this scenario, the key inputs for a gap analysis are already available: the current-state control inventory, the target baseline, and the applicable requirements. Therefore, the next step is to compare those inputs and document the deficiencies. This aligns with common security governance and risk practices described in sources such as NIST Cybersecurity Framework guidance and NIST SP 800-53/800-171 assessment approaches, where organizations assess implemented controls against required controls to identify shortcomings before planning remediation. After the gaps are identified, the organization would typically prioritize remediation based on risk, business impact, and compliance obligations.
- A. Correct.
Correct. A gap analysis is the process of comparing the current state to the desired future state or required baseline in order to identify deficiencies. Since the manager already has the current-state inventory, target baseline, and applicable requirements, the next logical step is to map current controls to those requirements and document where controls are absent, incomplete, or ineffective.
- B. Incorrect.
Incorrect. Remediation happens after the organization identifies and prioritizes the gaps. Starting remediation before formally documenting the differences between the current and target states can lead to wasted effort, missed requirements, and poor prioritization. This option reflects a common mistake of jumping to fixes before completing assessment activities.
- C. Incorrect.
Incorrect. A penetration test may be useful later to validate exploitability or control effectiveness, but it is not the next step in a gap analysis. Gap analysis is primarily a comparison exercise against a baseline, standard, or desired state. Penetration testing is a different assessment method and does not replace control mapping.
- D. Incorrect.
Incorrect. Tools can help with future assessments, but buying a new tool is not the next required action in the scenario. A gap analysis can be performed using existing documentation and processes. This choice confuses tooling decisions with the actual analytical task of identifying gaps.