Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 52 discussion

Actual exam question from ISC's CISSP
Question #: 52
Topic #: 1
[All CISSP Questions]

What is considered the BEST explanation when determining whether to provide remote network access to a third-party security service?

  • A. Contract negotiation
  • B. Supplier request
  • C. Business need
  • D. Vendor demonstration
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
stickerbush1970
Highly Voted 2 years, 2 months ago
Selected Answer: C
Third party accessing company assets will need a business need.
upvoted 14 times
jackdryan
1 year, 6 months ago
C is correct
upvoted 1 times
...
...
Nithstar
Most Recent 4 months ago
without a contract in place business need cannot suffice the requirement to grant network access so, A should be the correct answer
upvoted 1 times
...
Moose01
1 year, 1 month ago
A. all business requirements are addressed during contact negotiation. business needs falls under the one of the many terms in the contact.
upvoted 2 times
...
MD806
1 year, 2 months ago
Who determines the correct answer ? Seems like Most Voted is C but correct answer is A
upvoted 2 times
...
Bach1968
1 year, 4 months ago
Selected Answer: C
While contract negotiation (option A) is an important aspect of engaging with a third-party security service, it is not the BEST explanation when determining whether to provide remote network access to that service. The question specifically asks for the BEST explanation, and in this context, the primary consideration should be the business need (option C). Contract negotiation typically occurs after assessing the business need and deciding to proceed with engaging a third-party security service. During contract negotiation, the terms and conditions of the engagement are discussed and agreed upon, including aspects such as service levels, pricing, confidentiality, liability, and legal obligations. Therefore, while contract negotiation is relevant, option C (business need) is the BEST explanation for deciding whether to provide remote network access to a third-party security service.
upvoted 4 times
Jenkins3mol
6 months, 4 weeks ago
I agree with this explanation.
upvoted 1 times
...
...
KelvinYau
1 year, 5 months ago
Selected Answer: C
Providing remote network access to a third-party security service is a decision that should be made based on the specific business needs and the risks involved. It is important to evaluate the requirements for the service and whether it is critical for the business operations.
upvoted 1 times
...
s_n_
1 year, 9 months ago
The best explanation when determining whether to provide remote network access to a third-party security service is Business Need. Remote network access should only be provided if there is a specific business need that cannot be met without the service. It is important to consider the security implications of providing remote access and to ensure that the third-party service adheres to the organization's security policies and practices.
upvoted 1 times
...
Joadeika
1 year, 10 months ago
Selected Answer: A
All business need is addressed in contract negotiation
upvoted 2 times
dumdada
1 year, 5 months ago
You can have an unnecessary remote access in the contract even without a real business need. Business need is the key here
upvoted 1 times
...
...
cccispman
1 year, 11 months ago
Selected Answer: A
Surely, business need !
upvoted 1 times
...
somkiatr
1 year, 11 months ago
Selected Answer: A
I will select A. Third-Party Security Services Provider (TPSSP) The security roles and responsibilities of TPSSPs for: - Identity and access management - Cloud Workload Protection Platform - Network Security - Data & Storage Security - Assessment - Security Analytics as a Service - Application Security - Security Support Services Normally we need to negotiate roles & responsibilities of TPSSP. Service Level Agreement(SLAs) and types of support (On-site or Remote Access) have to be clarified. Reference : https://www.lexology.com/library/detail.aspx?g=3ed47921-2cfa-4d1b-8615-ad468a1cbc81
upvoted 1 times
...
KayChan
1 year, 11 months ago
Business need is a justification
upvoted 1 times
...
rootic
2 years ago
Selected Answer: C
Vote for C.
upvoted 1 times
...
DButtare
2 years, 2 months ago
Selected Answer: C
Is there a real need
upvoted 2 times
...
stickerbush1970
2 years, 2 months ago
Once the business need is determined, then a connection policy will be made.
upvoted 2 times
...
kptest12
2 years, 2 months ago
Answer is A For e.g , When working with a 3rd party on an internal project , if they need VPN access to meet the business need , the access is granted a part of contract negotiation .
upvoted 4 times
Joey456
2 years, 1 month ago
Disagree. Cyber policy dictates business needs for access. Not any element of the business contract. The 3rd party has NO RIGHTS to be on the network.
upvoted 2 times
...
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...