Security Assessment and TestingMedium

CISSP Practice Question: In a financial institution, which strategy is MOST effective for ensuring ongoing…

Published September 24, 2026 · Free daily CISSP practice question
In a financial institution, which strategy is MOST effective for ensuring ongoing compliance with security assessment standards?
  1. A.Continuous monitoring and assessment
  2. B.Annual security audits
  3. C.Ad-hoc testing based on resources
  4. D.Regular staff training on security policies
Correct answer: A. Continuous monitoring and assessment

Correct Answer: A. Continuous monitoring and assessment

Explanation (CISSP Manager Logic):

Continuous monitoring shifts security from a point-in-time event to an ongoing operational process, ensuring controls remain effective as the threat landscape evolves. This proactive approach aligns with risk management frameworks by providing real-time visibility into the organization's compliance posture.

By implementing this solution, you:

  • Enable rapid detection and remediation of control failures.
  • Support data-driven decision-making through real-time metrics.
  • Reduce the window of vulnerability between formal audit cycles.

While the other options are relevant, they fall short because:

  • B: Annual audits provide only a snapshot in time and become obsolete as soon as the environment changes.
  • C: Ad-hoc testing lacks the consistency and predictability required for a mature compliance program.
  • D: Training improves human behavior but does not validate the technical effectiveness of security controls.

Think like a manager:

Prioritize automated, persistent oversight over manual, periodic checks to maintain a resilient and compliant business environment.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions Next question →