After a gap analysis, the water utility lists missing MFA on VPN as a control gap versus policy. What does that gap analysis primarily represent?
Select an answer to reveal the explanation.
Short Explanation
Gap analysis is the honest checklist: 'here is where we are, here is where policy says we should be, and here is the missing brick.' Finding no MFA on VPN is naming the hole — not yet filling it, not yet hacking yourself.
Full Explanation
Gap analysis assesses differences between the current security state and a target state defined by policy, standards, or desired controls. Documenting missing MFA on VPN versus policy is a classic control gap finding. It is not synonymous with penetration testing, tabletop exercises, or implementing a compensating control; those may follow once gaps are prioritized. SY0-701 treats gap analysis as a fundamental security concept under 1.2.