exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 348 discussion

Actual exam question from ISC's CISSP
Question #: 348
Topic #: 1
[All CISSP Questions]

An organization outgrew its internal data center and is evaluating third-party hosting facilities. In this evaluation, which of the following is a PRIMARY factor for selection?

  • A. Facility provides an acceptable level of risk
  • B. Facility provides disaster recovery (DR) services
  • C. Facility has physical access protection measures
  • D. Facility provides the most cost-effective solution
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Highly Voted 2 years, 5 months ago
I choose "A", The risk over cost.
upvoted 15 times
1 year, 9 months ago
A is correct
upvoted 1 times
Most Recent 1 month, 2 weeks ago
Selected Answer: A
Too little information to make a good decision. A makes the most sense in terms of risk management. D would make sense if we knew what defined cost effective. Is it taking into account primary and secondary cost, cost in terms of cost-benefit analysis, or just the price?
upvoted 1 times
6 months, 1 week ago
Selected Answer: D
The answer D says it is a "cost" effective solution. Hence it is a solution.
upvoted 1 times
8 months, 2 weeks ago
Selected Answer: A
A for the test. D for real life.
upvoted 2 times
9 months, 1 week ago
I'm going with D as it focuses on the principle "most bang for my buck".
upvoted 1 times
1 year, 3 months ago
I say D...as a Manager, first thing I would look at is the budget, then consider the best options. The facility with the acceptable level of risk may be outside of the company's budget.
upvoted 3 times
1 year, 9 months ago
Selected Answer: A
Price is part of a risk assesment
upvoted 1 times
2 years ago
I vote for A. A facility that is cost-effective or has strong DR services may not necessarily provide an acceptable level of risk.
upvoted 1 times
2 years ago
Selected Answer: A
A - If the business simply can't afford it, its not a possibility
upvoted 2 times
2 years, 1 month ago
Selected Answer: A
A. Facility provides an acceptable level of risk is the PRIMARY factor for selection according to cissp. This includes evaluating the security measures in place at the facility, such as physical access controls, network security, and incident response capabilities, to ensure that the facility meets the organization's security requirements and provides an acceptable level of risk for the organization's data and operations. Other factors, such as disaster recovery services, physical access protection measures and cost-effectiveness may also be considered but the primary concern is ensuring that the facility provides an acceptable level of risk.
upvoted 2 times
2 years, 2 months ago
Selected Answer: A
I think of cost-benefit analysis contra cost-efficient. Meanwhile cost-efficient is pure about money, cost-benefit covers the balance between security, added value and cost. If i would prioritize cost before security, then i probably make a risk analysis and realize that OPEX/CAPEX of security controls will outpaces the price of more expensive but much safer hosting facility.
upvoted 1 times
2 years, 2 months ago
There are shared responsibilities between the customer and the Hosting providers. Hosting provider is not responsible to mitigate the customers' systems risk. This is the customer responsibility. And cost-effective does not mean no security. So I elect D.
upvoted 2 times
2 years, 2 months ago
Think like a Manager and get a more cost-effective solution with much quality.
upvoted 1 times
2 years, 2 months ago
Selected Answer: D
Since the organization outgrew the internal data center, it's looking for a cheaper solution for higher volumes of data. A is not the primary factor.
upvoted 2 times
2 years, 2 months ago
Selected Answer: A
Thinking like a CISO. B, C & D are all redundant if the facility does not provide an acceptable level of risk. I.e. You wouldn't take on unacceptable levels of risk to have DR, Physical access protection or to save money.
upvoted 1 times
2 years, 3 months ago
Selected Answer: A
B and C are all covered under A
upvoted 2 times
2 years, 4 months ago
As I think like a manager I agree with "D"
upvoted 2 times
Community vote distribution
A (35%)
C (25%)
B (20%)
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

Loading ...
Someone Bought Contributor Access for:
London, 1 minute ago