Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 234 discussion

Actual exam question from ISC's CISSP
Question #: 234
Topic #: 1
[All CISSP Questions]

A Chief Information Security Officer (CISO) of a firm which decided to migrate to cloud has been tasked with ensuring an optimal level of security. Which of the following would be the FIRST consideration?

  • A. Analyze the firm's applications and data repositories to determine the relevant control requirements.
  • B. Request a security risk assessment of the cloud vendor be completed by an independent third-party.
  • C. Define the cloud migration roadmap and set out which applications and data repositories should be moved into the cloud.
  • D. Ensure that the contract between the cloud vendor and the firm clearly defines responsibilities for operating security controls.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
sphenixfire
Highly Voted 1 year, 11 months ago
Selected Answer: A
you cannot define controls when you don't know which data an apps to protect and what the protection levels are need to be
upvoted 5 times
...
TheManiac
Most Recent 6 months, 1 week ago
Selected Answer: C
I would go for C. first step is to define
upvoted 1 times
...
eboehm
7 months, 2 weeks ago
This seems like a tricky question and I think too many people are jumping to answer A. I doubt the answer is a because there is no need for it. What security controls are needed is an easy answer. Its the same controls as for ANY 3rd party vendor.... you apply the same level of security as you would have internally.
upvoted 1 times
...
homeysl
8 months, 1 week ago
Selected Answer: C
The question is asking for FIRST step.
upvoted 1 times
...
gjimenezf
10 months, 1 week ago
Selected Answer: B
Before moving forward to anything with that provider, you need to make sure they have good risk assesment
upvoted 1 times
...
maawar83
11 months ago
Answer is C: The CISO Was tasked (made responsible). the CISO becomes the project manager there this question is more about the project management field therefore the C. "Define" becomes more relevant..
upvoted 1 times
...
thanhlb
1 year, 1 month ago
Selected Answer: A
(C) is a strategic decision that should be made after assessing the feasibility, benefits, and costs of migrating different assets and processes to the cloud, as well as the potential impact on the firm's operations and performance
upvoted 2 times
thanhlb
1 year, 1 month ago
A will help the CISO to identify the security risks, gaps, and needs of the firm's assets and processes, and to select the appropriate cloud service model and deployment model that can meet those requirements.
upvoted 1 times
...
...
74gjd_37
1 year, 2 months ago
Selected Answer: A
Option A (Analyze) is correct because before migrating to the cloud, it is essential to understand the applications and data repositories that need to be moved to the cloud and identify the relevant security controls required to protect them. This analysis helps in determining which cloud service provider to choose and what security controls should be implemented to ensure the optimal level of security. Once this analysis is done, the CISO can then move on to the other options mentioned to ensure a secure cloud migration.
upvoted 1 times
...
HughJassole
1 year, 4 months ago
B. The first step should be to verify that the vendor is following security practices: "Very often, you will have to rely on an external audit (ISO, SOC, etc.) conducted on the provider. These audits can provide an in-depth, objective, technical review of the third party’s security. What they demonstrate is that the vendor is trying to align their security program with a commonly accepted standard. These reports might be your best available resource for understanding a cloud provider’s risk—make sure you read them right." https://www.coalfire.com/the-coalfire-blog/third-party-risk-management-and-the-cloud
upvoted 1 times
...
Darealis
1 year, 10 months ago
Selected Answer: B
B. Request a security risk assessment of the cloud vendor be completed by an independent third-party. It is important to understand the security posture of the cloud vendor before moving any sensitive information or applications to the cloud. A security risk assessment can help identify any potential vulnerabilities or compliance issues with the vendor's controls and infrastructure, and allow the CISO to make an informed decision about whether to proceed with the migration and what measures need to be put in place to mitigate those risks.
upvoted 1 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
shash33
1 year, 10 months ago
Selected Answer: A
Defining the migration road map isn't CISO responsibility, and analyzing the firm's applications and data to determine the relevant control requirements comes before D. So i will go with A
upvoted 3 times
...
DJOEK
1 year, 10 months ago
Selected Answer: A
According to the Certified Information Systems Security Professional (CISSP) certification, the first consideration for a Chief Information Security Officer (CISO) tasked with ensuring an optimal level of security for a firm's migration to the cloud would be to "Analyze the firm's applications and data repositories to determine the relevant control requirements" (Option A). This includes identifying and classifying sensitive data and applications, assessing the current level of security for those assets, and determining the specific security controls that will be required to protect them in the cloud environment. This step is critical because it helps the CISO understand the scope of the migration and ensure that the appropriate security controls are implemented to protect the firm's sensitive data and systems. The other options are important steps as well but it is important to understand that the first step is identifying and assessing the security requirement for the data and system that are to be migrated into the cloud.
upvoted 2 times
...
rajkamal0
1 year, 11 months ago
Selected Answer: C
Thinking from CISO's view, C is the best answer.
upvoted 1 times
...
oudmaster
1 year, 11 months ago
As a CISO, his daily job is to know and work on the Apps/data and what security control is required. I exclude A. I see option C is the right one.
upvoted 1 times
...
ringoru
1 year, 11 months ago
Selected Answer: D
Answer is D. They key words in the question used were "optimal level of security". Answer D is the only one related to the question asked about security.
upvoted 2 times
oudmaster
1 year, 11 months ago
The questions says "first consideration". So D comes after C. You should know what applications are going to be migrated to the cloud and what cloud security you will need in first place. Then come to see what is your security responsibility vs cloud provider responsibility.
upvoted 2 times
...
...
BP_lobster
2 years ago
Selected Answer: D
B&C depend on D. A is inefficient as cloud migration may not affect/cover all applications. Without clear responsibilities (for operating security controls) you cannot define a migration roadmap or maintain a "secure" cloud environment. How will you know who secures what? How will you know which pieces of the cloud vendors "secure" architecture you are supposed to maintain?
upvoted 2 times
...
franbarpro
2 years, 1 month ago
Selected Answer: C
The FIRST thing to consider is planning. So, yea "C". | And I am thinking like a manager here.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...