CISSP Practice Question: In a healthcare organization with budget constraints, what is the BEST way…
Correct Answer: C. Conduct a risk assessment and align investments
Explanation (CISSP Manager Logic):
A risk assessment provides the objective data necessary to prioritize limited resources by identifying the most significant threats to organizational assets. This ensures that security spending is a strategic business decision rather than a reactive technical purchase.
By conducting a risk assessment, you:
- Align security expenditures with business objectives and risk appetite.
- Justify budget requests to stakeholders using data-driven evidence.
- Ensure compliance with regulatory requirements like HIPAA.
While the other options are relevant, they fall short because:
- A: Physical security is only one component of a defense-in-depth strategy and may not address the highest risks.
- B: Endpoint protection is a tactical tool that should be deployed only after a risk assessment confirms its necessity.
- D: Infrastructure upgrades are operational improvements that do not inherently address specific security vulnerabilities.
Think like a manager:
Never commit resources without first understanding the risk landscape. Effective security management requires balancing cost against the potential impact of a realized threat.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial