exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 180 discussion

Actual exam question from ISC's CISSP
Question #: 180
Topic #: 1
[All CISSP Questions]

What is considered a compensating control for not having electrical surge protectors installed?

  • A. Having dual lines to network service providers built to the site
  • B. Having a hot disaster recovery (DR) environment for the site
  • C. Having network equipment in active-active clusters at the site
  • D. Having backup diesel generators installed to the site
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bhuraw
Highly Voted 2 years, 3 months ago
very very unreal scenario. They haven't money for Surge protectors but want DR capabilities
upvoted 18 times
klarak
10 months, 1 week ago
Exactly. Dumb question. Still, won't keep it off the exam...
upvoted 1 times
...
Mann0302
2 years, 2 months ago
Exactly, the question doesn't even make sense smh.
upvoted 5 times
...
jackdryan
1 year, 9 months ago
B is correct
upvoted 3 times
...
...
Humongous1593
Highly Voted 2 years, 4 months ago
Selected Answer: B
Key here is "the site". If surge hits and nothing is protecting the hardware the entire site could be down and PSU fried. DR site would be elsewhere and be unaffected.
upvoted 7 times
...
Tuhaar
Most Recent 2 months, 1 week ago
Selected Answer: B
sorry guys option B after rethinking this. Generator does not help with surges, it restores power. In case there is a surge and the servers are toast, there is no business continuity at which time the DR comes handy. Though expensive than a generator from a compensating control DR makes sense
upvoted 1 times
...
Tuhaar
2 months, 1 week ago
Selected Answer: D
A hot disaster recovery (DR) site is designed to take over operations in the event of a major failure or disaster, ensuring business continuity. However, it doesn't specifically address the issue of electrical surges at the primary site. Electrical surge protectors are meant to protect equipment from voltage spikes that can cause immediate damage or degrade the performance of electronic components over time12. Backup diesel generators, on the other hand, can provide a continuous power supply during electrical disturbances, including surges, thereby directly mitigating the risk associated with not having surge protectors
upvoted 1 times
...
Tuhaar
2 months, 3 weeks ago
Selected Answer: D
The CISSP Official Study Guide, Domain 7 (Security Operations), discusses compensating controls as alternative measures designed to mitigate risks when primary controls are absent. Backup power solutions, like diesel generators, are commonly cited as compensating controls for electrical power risks, including surges and outages.
upvoted 1 times
...
stack120566
2 months, 3 weeks ago
Selected Answer: D
The answers would make a little more sense if it were worded you do not have a backup generator what would be a compensating control. or you do not have UPS what would be a compensating control.
upvoted 1 times
...
stack120566
2 months, 3 weeks ago
Selected Answer: D
You walk up to the director of IT and say we do not ahve surge protection, but dont worry we have an hot site avialable. You are looking for a job becuse you are too stupid to requisition surrge protectors .
upvoted 1 times
...
CCNPWILL
8 months, 3 weeks ago
Selected Answer: D
HOT site is better than having diesel generators? i mean thats not a realistic implementation of this. Having backup ANY kind of generators would be suffice generally and is a more realistic answer to such scenario. I have to go against the grain. D
upvoted 1 times
Zapepelele
2 months, 2 weeks ago
A big electrical surge without protection can cause damaged to electrical infrastructure... so, it doesn't matter if you have 1 Diesel generator or fifty, you will be down anyway.
upvoted 2 times
...
...
eboehm
10 months, 2 weeks ago
Selected Answer: C
interesting that literally every question here seems wrong. The question isnt about loss of power. Does literally no one know what a surge protector does? Surge protector is not a control protecting the entire building. Therefore a DR hot site and a backup generator is overkill. A generator would be a compensating control for UPS but not a surge protector. Surge protectors are controls that protect a piece of equipment. Therefore a valid compensating control would be having redundancy for that system. AKA active/active clusters ---> network equipment can apply to servers as well
upvoted 1 times
...
Vasyamba1
11 months, 1 week ago
Selected Answer: D
I don't think B is a correct answer. Imagine you are a manager, you come to the director of the company and he said "Look, we don't have surge protectors. What are we going to do when a surge happens?" You say "No worries, we will just move to another buillding!" :)
upvoted 1 times
...
629f731
1 year, 1 month ago
Selected Answer: D
If we think as a Manager, and the main problem is power failures, a "compensatory control" that is, not the best solution but something that helps when the best option which is a DR site is not viable, is having "backup diesel generators ". I go with D
upvoted 1 times
...
maawar83
1 year, 1 month ago
Agree the question does not make a lot of sense.. but thinking for cost effective and considering that no surge protectors... it is very expensive to have hot disaster recovery DR... looking at C. active-active to clusters... can ensure data protection and integrity and availability considering that clusters are connected to different power sources.. I think C. can be a good answer as well.
upvoted 1 times
...
Soleandheel
1 year, 2 months ago
In the event of electrical surges that could potentially damage systems, a hot DR environment provides redundancy by replicating critical systems and data in a separate location. This ensures that essential services can quickly fail over to the DR environment, minimizing downtime and data loss.
upvoted 1 times
Soleandheel
1 year, 2 months ago
B. Having a hot disaster recovery (DR) environment for the site
upvoted 1 times
...
...
Zonas
1 year, 2 months ago
D is correct
upvoted 1 times
...
homeysl
1 year, 4 months ago
Selected Answer: B
Other answers don't make sense with the given scenario
upvoted 1 times
...
Dam0s
1 year, 4 months ago
Selected Answer: B
If an electrical surge occurs, the systems themselves could be fried. An alternate source of power like a diesel generator will not help. They only solution to frying your actual systems from these options is an alternate DR site.
upvoted 2 times
...
74gjd_37
1 year, 5 months ago
Selected Answer: D
In a scenario where a surge hits and nothing is protecting the hardware, then the entire site could potentially go down, which could result in damage to PSUs and other equipment. However, from a compensating control perspective in the context of the CISSP exam, backup diesel generators are often considered to be a valid compensating control for mitigating the loss of power that can result from electrical surges.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago