Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 213 discussion

Actual exam question from ISC's CISSP
Question #: 213
Topic #: 1
[All CISSP Questions]

Which of the following outsourcing agreement provisions has the HIGHEST priority from a security operations perspective?

  • A. Conditions to prevent the use of subcontractors
  • B. Terms for contract renegotiation in case of disaster
  • C. Root cause analysis for application performance issue
  • D. Escalation process for problem resolution during incidents
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
Vasyamba1
8 months ago
Selected Answer: C
The root cause analysis often highlights issues that require remediation to prevent similar incidents in the future, so I think it's the most important thing for SecOps.
upvoted 2 times
...
maawar83
10 months, 3 weeks ago
I think the answer is C. A and B.. are not valid for security operation.. D is the escalation process for problem during incident... C... will make more sense as RCA for application performance issue that can be cause by Cyber Attack?
upvoted 2 times
...
homeysl
1 year, 1 month ago
Selected Answer: D
D. It's between A and D but the question mentioned security operations.
upvoted 2 times
...
74gjd_37
1 year, 2 months ago
Selected Answer: D
Option D, Escalation process for problem resolution during incidents, ensures that there is a clear and effective process in place for resolving security incidents and minimizing the impact of any security breaches. It is critical to have a well-defined escalation process to ensure that security incidents are handled promptly and efficiently. The other provisions listed are also important, but they do not have as high a priority from a security operations perspective as the escalation process for problem resolution during incidents. An escalation process is necessary for resolving security incidents promptly and efficiently. Outsourcing agreements transfer responsibility and control of certain business functions to a third-party provider, but ultimate responsibility for information security still rests with the organization. Therefore, an escalation process helps maintain security posture and communication and accountability between the organization and the outsourcing provider.
upvoted 2 times
...
HughJassole
1 year, 5 months ago
The question doesn't mention what is being outsourced, so D might not be applicable. What if you're outsourcing the cafeteria? A seems to be the best answer, I once used a contractor to do construction and he subcontracted work, it had to be redone. Avoid subcontractors if you can.
upvoted 2 times
...
dmo_d
1 year, 6 months ago
Selected Answer: D
I'm going for D. Subcontractors aren't the HIGHEST concern. Yes, it elevates the risks. But, without proper incident handling "our" business could make huge losses. Therefore this is the highest priority of the given options.
upvoted 1 times
...
DJOEK
1 year, 10 months ago
Selected Answer: D
According to the International Association of Computer Science and Information Technology (IACSIT), the outsourcing agreement provision with the highest priority from a security operations perspective is the escalation process for problem resolution during incidents. This is because it is important for organizations to have a clear and efficient process in place for resolving problems that may arise during an incident, in order to minimize the impact on the organization and maintain the security of its systems and data. Other provisions, such as those related to subcontracting and contract renegotiation, may also be important for ensuring the security and integrity of the organization's systems, but the escalation process for problem resolution is typically considered the most critical from a security operations perspective.
upvoted 2 times
jackdryan
1 year, 6 months ago
D is correct
upvoted 1 times
...
...
oudmaster
1 year, 11 months ago
If Third-Party Governance process is well managed, then A is excluded. I would go with D.
upvoted 1 times
...
sphenixfire
1 year, 11 months ago
Selected Answer: A
very unclear state questions. anoying. I go for a, most of the rest is not security but system operations
upvoted 2 times
dmo_d
1 year, 6 months ago
Information security incidents have noot necessarily to do with systems operations. An incident could be that the outsourcing contractor looses some sensitive hardcopy information. This would be covered by proper incident handling.
upvoted 1 times
...
...
Jamati
2 years ago
Selected Answer: D
Agreed, D
upvoted 1 times
...
sec_007
2 years, 1 month ago
Selected Answer: A
Will go with A. Subcontracting increases security risk and compliance perimeter, and ensuring everything is compliant from security point of view is highest priority. Reference: https://softwarehut.com/blog/it-outsourcing/outsourcing-contract-clauses
upvoted 1 times
dmo_d
1 year, 6 months ago
sure about that? For me it is more important that the subcontractors are carefully selected. And much more important is that there is proper incident handling. No one likes if the contractor doesn't provide emergency contact details or handles high priority incidents very slowly.
upvoted 1 times
...
...
BDSec
2 years, 2 months ago
Selected Answer: D
D first, A would be second
upvoted 2 times
...
matt1976
2 years, 2 months ago
you are correct, its A. Not quite sure what I was thinking there.
upvoted 1 times
matt1976
2 years, 2 months ago
Geez, I mean D. Someone give me a drink
upvoted 6 times
...
...
CuteRabbit168
2 years, 2 months ago
Selected Answer: D
Selecting D. Question is from security operations (SOC ?) perspective
upvoted 3 times
...
matt1976
2 years, 2 months ago
Answer is A. Its pretty obvious
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...