CISSP Practice Question: What would MOST likely happen if a financial institution decides to cut…
Correct Answer: C. Delayed response to security incidents
Explanation (CISSP Manager Logic):
Reducing monitoring capabilities diminishes visibility, directly increasing the Mean Time to Detect (MTTD) and Mean Time to Respond (MTTR). From a business perspective, this "blind spot" allows threats to persist longer, significantly increasing the potential financial and operational impact of a breach.
By maintaining robust monitoring, you:
- Enable rapid identification of anomalous behavior.
- Minimize the dwell time of malicious actors.
- Support data-driven incident response and forensic investigations.
While the other options are relevant, they fall short because:
- A: Reducing resources decreases visibility, making it less likely to detect sophisticated attacks.
- B: Risk increases when monitoring is cut because the organization loses its ability to proactively mitigate threats.
- D: Most frameworks mandate continuous monitoring; cutting these costs likely leads to non-compliance.
Think like a manager:
Security is a business enabler that requires balancing operational costs against risk appetite. Cutting essential visibility is a false economy that trades short-term budget gains for catastrophic long-term liability.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial