CISSP Practice Question: In a large financial institution with limited security testing budget, which approach…
Correct Answer: A. Prioritize testing based on risk assessment results
Explanation (CISSP Manager Logic):
Risk-based prioritization ensures limited resources are directed toward assets with the highest impact and likelihood of exploitation. This approach aligns security spending with business objectives, ensuring critical financial data receives the most rigorous scrutiny.
By prioritizing testing based on risk, you:
- Maximize the return on investment for a limited security budget.
- Address the most significant threats to organizational stability first.
- Satisfy regulatory expectations for a proactive, risk-managed posture.
While the other options are relevant, they fall short because:
- B: Equal distribution wastes resources on low-value systems while leaving high-risk assets under-protected.
- C: Focusing only on the perimeter ignores internal threats and the risk of lateral movement.
- D: Compliance is a baseline requirement that often misses business-specific risks and operational threats.
Think like a manager:
Security is a risk management function where resource allocation must be based on the potential impact to the organization's mission and bottom line.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial