CISSP Practice Question: In a medium-sized healthcare organization facing budget constraints, what is the BEST…
Correct Answer: B. Conduct a risk assessment
Explanation (CISSP Manager Logic):
A risk assessment is the foundational step for any security initiative, especially when resources are limited. It allows management to identify specific threats to HIPAA-regulated data and prioritize security investments based on actual business impact rather than guesswork.
By conducting a risk assessment, you:
- Identify and prioritize vulnerabilities specific to the healthcare environment.
- Ensure security spending is targeted toward the highest-risk areas.
- Establish the necessary documentation required for HIPAA regulatory compliance.
While the other options are relevant, they fall short because:
- A: Zero-trust is a complex architectural strategy that requires significant capital and time, making it impractical without first justifying the need.
- C: Centralized logging is a technical control that improves visibility but does not provide a strategic roadmap for overall risk mitigation.
- D: Training is a critical administrative control, but its content should be informed by the risks identified during a formal assessment.
Think like a manager:
Always identify the "why" before the "how." In a resource-constrained environment, you must use risk data to justify every dollar spent on security architecture.
Ready to find out if you'd pass?
5,000+ expert-calibrated questions, adaptive CAT mock exams, and gap analysis that shows exactly what to study next.
Try 5 free questions Start 7-day free trial