Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 348 discussion

Actual exam question from ISC's CISSP
Question #: 348
Topic #: 1
[All CISSP Questions]

An organization outgrew its internal data center and is evaluating third-party hosting facilities. In this evaluation, which of the following is a PRIMARY factor for selection?

  • A. Facility provides an acceptable level of risk
  • B. Facility provides disaster recovery (DR) services
  • C. Facility has physical access protection measures
  • D. Facility provides the most cost-effective solution
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
ItsBananass
Highly Voted 2 years, 2 months ago
I choose "A", The risk over cost.
upvoted 14 times
jackdryan
1 year, 6 months ago
A is correct
upvoted 1 times
...
...
Dtony66
Most Recent 3 months, 1 week ago
Selected Answer: D
The answer D says it is a "cost" effective solution. Hence it is a solution.
upvoted 1 times
...
Skittle4710
5 months, 2 weeks ago
Selected Answer: A
A for the test. D for real life.
upvoted 1 times
...
041ba31
6 months, 1 week ago
I'm going with D as it focuses on the principle "most bang for my buck".
upvoted 1 times
...
shmoeee
1 year ago
I say D...as a Manager, first thing I would look at is the budget, then consider the best options. The facility with the acceptable level of risk may be outside of the company's budget.
upvoted 3 times
...
Tygrond87
1 year, 6 months ago
Selected Answer: A
Price is part of a risk assesment
upvoted 1 times
...
Rollingalx
1 year, 9 months ago
I vote for A. A facility that is cost-effective or has strong DR services may not necessarily provide an acceptable level of risk.
upvoted 1 times
...
Berto
1 year, 9 months ago
Selected Answer: A
A - If the business simply can't afford it, its not a possibility
upvoted 2 times
...
DJOEK
1 year, 10 months ago
Selected Answer: A
A. Facility provides an acceptable level of risk is the PRIMARY factor for selection according to cissp. This includes evaluating the security measures in place at the facility, such as physical access controls, network security, and incident response capabilities, to ensure that the facility meets the organization's security requirements and provides an acceptable level of risk for the organization's data and operations. Other factors, such as disaster recovery services, physical access protection measures and cost-effectiveness may also be considered but the primary concern is ensuring that the facility provides an acceptable level of risk.
upvoted 2 times
...
eddievonbahnhof
1 year, 11 months ago
Selected Answer: A
I think of cost-benefit analysis contra cost-efficient. Meanwhile cost-efficient is pure about money, cost-benefit covers the balance between security, added value and cost. If i would prioritize cost before security, then i probably make a risk analysis and realize that OPEX/CAPEX of security controls will outpaces the price of more expensive but much safer hosting facility.
upvoted 1 times
...
oudmaster
1 year, 11 months ago
There are shared responsibilities between the customer and the Hosting providers. Hosting provider is not responsible to mitigate the customers' systems risk. This is the customer responsibility. And cost-effective does not mean no security. So I elect D.
upvoted 2 times
...
Mann0302
1 year, 11 months ago
Think like a Manager and get a more cost-effective solution with much quality.
upvoted 1 times
...
PeepoK
1 year, 11 months ago
Selected Answer: D
Since the organization outgrew the internal data center, it's looking for a cheaper solution for higher volumes of data. A is not the primary factor.
upvoted 2 times
...
BP_lobster
1 year, 11 months ago
Selected Answer: A
Thinking like a CISO. B, C & D are all redundant if the facility does not provide an acceptable level of risk. I.e. You wouldn't take on unacceptable levels of risk to have DR, Physical access protection or to save money.
upvoted 1 times
...
Jamati
2 years ago
Selected Answer: A
B and C are all covered under A
upvoted 2 times
...
franbarpro
2 years ago
As I think like a manager I agree with "D"
upvoted 2 times
...
sec_007
2 years, 1 month ago
Selected Answer: D
The benefits of DCO may include reduced operational costs, more efficient use of infrastructure, and access to more server, storage or computing capacity on demand. The risks include lack of control over security and disaster recovery, lack of flexibility, problems with SLA fulfillment and vendor lock-in.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...