CISSP Practice Question: In a large financial institution, what would MOST likely happen if the…
Correct Answer: A. Increased vulnerability exposure
Explanation (CISSP Manager Logic):
Delaying code reviews allows security flaws to migrate into production, increasing technical debt and the organizational attack surface. From a risk management perspective, failing to identify vulnerabilities early in the SDLC elevates the likelihood of data breaches and regulatory non-compliance.
By implementing code reviews, you:
- Reduce the attack surface through early flaw detection.
- Lower the total cost of ownership by fixing bugs before deployment.
- Ensure alignment with security frameworks and compliance mandates.
While the other options are relevant, they fall short because:
- B: Skipping security checks creates "false speed" that is eventually lost to emergency patching and rework.
- C: Security friction and poor code quality typically degrade team morale and cross-departmental trust.
- D: The long-term costs of incident response and remediation far outweigh short-term operational savings.
Think like a manager:
Prioritize proactive security controls over reactive recovery to protect the business from catastrophic financial and reputational damage. Security must be integrated into the SDLC to ensure long-term operational resilience.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial