CISSP Practice Question: In a healthcare organization under tight budget constraints, what would MOST likely…
Correct Answer: A. Increased likelihood of undetected vulnerabilities
Explanation (CISSP Manager Logic):
Security testing is a critical detective control that validates the effectiveness of the security posture. Delaying these assessments creates a visibility gap, allowing technical debt and unpatched weaknesses to accumulate, which significantly increases the organization's risk exposure.
By maintaining regular testing, you:
- Identify and remediate risks before they are exploited by adversaries.
- Provide objective assurance that security controls are functioning as intended.
- Support data-driven resource allocation for future security investments.
While the other options are relevant, they fall short because:
- B: Short-term savings are eclipsed by the catastrophic long-term costs of a data breach or system downtime.
- C: Regulatory frameworks like HIPAA require periodic technical evaluations; delaying them leads to non-compliance.
- D: Stakeholder trust is built on transparency and rigorous oversight, not on the reduction of security due diligence.
Think like a manager:
Risk cannot be managed if it is not measured. Prioritizing immediate budget relief over continuous monitoring is a strategic failure that trades long-term organizational resilience for temporary financial optics.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial