Security Assessment and TestingMedium

CISSP Practice Question: In a healthcare organization facing budget constraints, which strategy is BEST for…

Published October 10, 2026 · Free daily CISSP practice question
In a healthcare organization facing budget constraints, which strategy is BEST for prioritizing security assessments?
  1. A.Focus on high-risk systems first
  2. B.Conduct assessments based on vendor recommendations
  3. C.Implement a quarterly assessment schedule
  4. D.Select systems based on user feedback
Correct answer: A. Focus on high-risk systems first

Correct Answer: A. Focus on high-risk systems first

Explanation (CISSP Manager Logic):

When resources are limited, managers must adopt a risk-based approach to ensure security efforts align with business impact. Prioritizing high-risk systems ensures that the most critical assets—those vital to patient safety and data integrity—receive immediate attention.

By focusing on high-risk systems, you:

  • Optimize the allocation of limited budgetary and human resources.
  • Reduce the organization's overall risk profile more effectively.
  • Ensure compliance by protecting the most sensitive health data first.

While the other options are relevant, they fall short because:

  • B: Vendor recommendations prioritize specific products rather than the organization's unique risk landscape.
  • C: Rigid schedules ignore dynamic threats and may waste resources on low-impact systems.
  • D: User feedback is subjective and does not reflect technical or business criticality.

Think like a manager:

Prioritization is a core management function; always allocate resources where they provide the greatest risk reduction and support business continuity.

Ready to find out if you'd pass?

5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.

Try 5 free questions Start 7-day free trial
← Previous question All questions