CISSP Practice Question: In a medium-sized financial organization, which approach BEST balances security and budget…
Correct Answer: C. Adopting a risk-based asset protection strategy
Explanation (CISSP Manager Logic):
A risk-based approach ensures that security investments are proportional to the value of the assets and the likelihood of threats. This allows management to prioritize high-value assets and critical risks, ensuring the most efficient use of limited financial and human resources.
By adopting a risk-based strategy, you:
- Align security spending with organizational risk appetite.
- Prioritize protection for the most critical business assets.
- Provide data-driven justification for budget allocations.
While the other options are relevant, they fall short because:
- A: Training is a vital administrative control but does not provide a framework for technical or physical asset prioritization.
- B: Advanced detection systems are often expensive capital expenditures that may not address the organization's specific high-priority risks.
- D: Compliance audits verify adherence to standards but do not necessarily result in an optimized or proactive risk posture.
Think like a manager:
Security is a business enabler, not a bottomless pit for spending. Always prioritize resource allocation based on the potential impact on the organization's mission and bottom line.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial