CISSP Practice Question: A medium-sized healthcare organization is evaluating its risk management strategy amid increasing…
Correct Answer: A. Conduct a comprehensive risk assessment
Explanation (CISSP Manager Logic):
Risk assessment is the foundational step that allows management to identify, prioritize, and mitigate risks based on the organization's specific threat landscape and regulatory requirements. This ensures security investments are cost-effective and aligned with the business's risk appetite rather than applying controls blindly.
By conducting a risk assessment, you:
- Identify high-priority vulnerabilities and regulatory gaps.
- Justify security spending through data-driven decision-making.
- Establish a baseline for measuring the effectiveness of future controls.
While the other options are relevant, they fall short because:
- B: Encryption is a specific technical control that may be unnecessary or inefficient without first identifying where the actual risk lies.
- C: Outsourcing transfers operational tasks but never relieves the organization of its ultimate legal and regulatory accountability.
- D: Training is a critical administrative control but cannot be effectively tailored without understanding the specific risks the organization faces.
Think like a manager:
Always assess before you act. Effective risk management requires a top-down approach where data-driven analysis dictates strategy and resource allocation.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial