exam questions

Exam CCSP All Questions

View all questions & answers for the CCSP exam

Exam CCSP topic 1 question 309 discussion

Actual exam question from ISC's CCSP
Question #: 309
Topic #: 1
[All CCSP Questions]

Security is a critical yet often overlooked consideration for BCDR planning.
At which stage of the planning process should security be involved?

  • A. Scope definition
  • B. Requirements gathering
  • C. Analysis
  • D. Risk assessment
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️
Defining the scope of the plan is the very first step in the overall process. Security should be included from the very earliest stages and throughout the entire process. Bringing in security at a later stage can lead to additional costs and time delays to compensate for gaps in planning. Risk assessment, requirements gathering, and analysis are all later steps in the process, and adding in security at any of those points can potentially cause increased costs and time delays.

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
MaciekMT
1 month, 2 weeks ago
Selected Answer: B
Security should be involved as early as possible in the Business Continuity and Disaster Recovery (BCDR) planning process. The best stage to introduce security considerations is during requirements gathering, where the organization defines critical business functions, dependencies, and security needs. Security is integral to BCDR planning, ensuring that recovery strategies do not introduce vulnerabilities. This phase defines access controls, encryption, backup security, and compliance requirements. Early involvement of security helps ensure that BCDR plans align with organizational security policies and regulations (e.g., GDPR, HIPAA). A. Scope Definition → Defines high-level objectives but does not include detailed security requirements yet.
upvoted 1 times
...
kepalon
6 months, 3 weeks ago
Selected Answer: A
A is the correct answer. Security from the beginning.
upvoted 2 times
...
VSN80
1 year, 4 months ago
security should be defined at early stage. Answer is correct
upvoted 2 times
...
Sa007788
1 year, 8 months ago
in scope defintion phase we focus only in definition onf critical business service, why security is included, basically it need to be addedd in the phase of gathering, more logical i think
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago