Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 102 discussion

Actual exam question from ISC's CISSP
Question #: 102
Topic #: 1
[All CISSP Questions]

What is the MAIN purpose of a security assessment plan?

  • A. Provide education to employees on security and privacy, to ensure their awareness on policies and procedures.
  • B. Provide the objectives for the security and privacy control assessments and a detailed roadmap of how to conduct such assessments.
  • C. Provide guidance on security requirements, to ensure the identified security risks are properly addressed based on the recommendation.
  • D. Provide technical information to executives to help them understand information security postures and secure funding.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
YesPlease
11 months, 3 weeks ago
Selected Answer: B
Answer B) Keyword in question is "plan" and the only sentence that refers to a plan is "The objectives for the control assessments and a detailed roadmap of how to conduct such assessments."
upvoted 2 times
...
Bach1968
1 year, 4 months ago
Selected Answer: B
The MAIN purpose of a security assessment plan is: B. Provide the objectives for the security and privacy control assessments and a detailed roadmap of how to conduct such assessments. A security assessment plan outlines the objectives, scope, methodology, and approach for conducting security and privacy control assessments within an organization. Its primary purpose is to provide a clear roadmap and guidance on how to assess and evaluate the effectiveness of security controls in place.
upvoted 2 times
...
HughJassole
1 year, 5 months ago
B: "The objectives for the control assessments and a detailed roadmap of how to conduct such assessments." https://csrc.nist.gov/glossary/term/assessment_plan
upvoted 3 times
...
HughJassole
1 year, 6 months ago
Def B: https://csrc.nist.gov/glossary/term/assessment_plan
upvoted 4 times
SSimko
10 months ago
Agreed, it is literally the definition.
upvoted 1 times
...
...
Jamati
2 years ago
Selected Answer: B
Clearly the answer is B here. Before conducting a security assessment, you need to know the objectives of that assessment, and all objectives must be SMART (Specific, Measurable, Attainable/Achievable, Relevant, Time-bound).
upvoted 2 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
Rollizo
2 years, 1 month ago
the key here is "plan": security assessment plan => objectives
upvoted 2 times
...
dev46
2 years, 2 months ago
B could be right, but D sounds right too I have been engaged with a few initiatives where executives want to conduct security assessments and see if it's financially viable to kick off the project or not.
upvoted 2 times
franbarpro
2 years, 1 month ago
It cannot be "D" - CEOs pay us to translate technical info into the lengo they understand.
upvoted 1 times
...
...
CuteRabbit168
2 years, 2 months ago
Selected Answer: B
Answer is correct
upvoted 3 times
...
DERCHEF2009
2 years, 2 months ago
Selected Answer: A
A is correct
upvoted 1 times
DERCHEF2009
2 years, 2 months ago
Sorry B
upvoted 4 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...