CISSP Practice Question: What would MOST likely happen if an organization does not regularly update…
Correct Answer: A. Increased vulnerability to attacks
Explanation (CISSP Manager Logic):
Failing to update protocols creates technical debt and security gaps that adversaries exploit through known vulnerabilities. From a business perspective, outdated standards weaken the defensive posture, directly increasing the risk of data breaches and operational downtime.
By maintaining current protocols, you:
- Reduce the attack surface against evolving threat vectors.
- Ensure alignment with industry best practices and security frameworks.
- Protect the integrity and confidentiality of organizational data.
While the other options are relevant, they fall short because:
- B: Outdated protocols typically lead to non-compliance with modern regulatory requirements like GDPR or PCI-DSS.
- C: Security updates rarely improve user experience and often introduce friction through stricter authentication.
- D: Skipping updates saves immediate costs but leads to higher long-term expenses through incident response.
Think like a manager:
Proactive lifecycle management is a core component of due care. Managers must balance operational continuity with the strategic necessity of patching to mitigate enterprise risk.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial