Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.
exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 343 discussion

Actual exam question from ISC's CISSP
Question #: 343
Topic #: 1
[All CISSP Questions]

Which is the PRIMARY mechanism for providing the workforce with the information needed to protect an agency's vital information resources?

  • A. Implementation of access provisioning process for coordinating the creation of user accounts
  • B. Incorporating security awareness and training as part of the overall information security program
  • C. An information technology (IT) security policy to preserve the confidentiality, integrity, and availability of systems
  • D. Execution of periodic security and privacy assessments to the organization
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
WiDeBarulho
Highly Voted 2 years, 1 month ago
Selected Answer: B
Security awareness and training will give you CIA (option "C"). This training will/shall also cover the concepts of need-to-know and least privilege (option "A"). Therefore option "B" is the most appropriate.
upvoted 10 times
jackdryan
1 year, 6 months ago
B is correct
upvoted 1 times
...
...
Jay327
Highly Voted 2 years ago
Selected Answer: C
I vote C "PRIMARY mechanism" Policy comes first and will include awareness and training program? Think like a manager :)
upvoted 6 times
eboehm
7 months, 2 weeks ago
did you even read the question? This is one of those questions that will get you in trouble by auto selecting an answer just cuz it has a policy in it. For one thing, this states an information technology policy. That tends to not be people/process specific. Secondly, yes there would be a policy in place. BUT a policy is not the way you PROVIDE users with the required information as the question asks
upvoted 2 times
...
oudmaster
1 year, 11 months ago
I agree with you. Security Policy can include many points other than user training, and it should provide enough/complete security to protect vital information assets.
upvoted 3 times
...
ap0ls
8 months, 2 weeks ago
Agree. Go with the more general or broader answer
upvoted 1 times
...
...
8e1c45b
Most Recent 4 months, 1 week ago
Selected Answer: B
vote for b
upvoted 1 times
...
YesPlease
11 months, 1 week ago
Selected Answer: B
Answer B) Incorporating security awareness and training as part of the overall information security program Answer B includes C since it references an "overall information security program". C does not need to contain anything about end user training.
upvoted 1 times
...
isaac592
1 year, 1 month ago
Selected Answer: B
B - "providing the workforce"
upvoted 3 times
isaac592
1 year, 1 month ago
Also, is states it verbatim in NIST SP800 Ch4: "Establishing and maintaining a robust and relevant information security awareness and training program as part of the overall information security program is the primary conduit for providing the workforce with the information and tools needed to protect an agency’s vital information resources."
upvoted 5 times
...
...
BoyBastos
1 year, 2 months ago
Selected Answer: B
B. Incorporating security awareness and training as part of the overall information security program Incorporating security awareness and training as part of the overall information security program is the primary mechanism for providing the workforce with the information needed to protect an agency's vital information resources. Educating employees and users about security risks, best practices, policies, and procedures helps them understand their roles and responsibilities in safeguarding information resources. While the other options (implementation of access provisioning process, IT security policy, periodic security assessments) are important components of an information security program, security awareness and training play a critical role in ensuring that the workforce is informed and capable of protecting information resources effectively.
upvoted 3 times
...
dark7ness
1 year, 4 months ago
Selected Answer: B
Security awareness is essential
upvoted 1 times
...
HughJassole
1 year, 5 months ago
B. "providing the workforce with the information" sounds like training of employees, hence B is the only match. C wouldn't work because it doesn't train and it is too specific. At my CISSP class the instructor cautioned against too specific of an answer, the strategy is to go with the most comprehensive since CISSP is about high level, not the details.
upvoted 1 times
...
JohnyDal
1 year, 9 months ago
Selected Answer: C
Think like a manager.....policy includes A,B,D....so C is the all-encompassing best managerial answer
upvoted 3 times
...
Dee83
1 year, 9 months ago
B. Incorporating security awareness and training as part of the overall information security program.
upvoted 1 times
...
DJOEK
1 year, 10 months ago
Selected Answer: B
keyword "Workforce" should be correct answer B
upvoted 1 times
...
IXone
2 years ago
Selected Answer: B
keyword "Workforce" should be correct answer B
upvoted 1 times
...
pingundas
2 years ago
Policies are information with instructions (must/must not). C seems to be right to me
upvoted 2 times
...
franbarpro
2 years, 1 month ago
The questions says "providing the workforce with the information needed" - That sounds like training to me.
upvoted 5 times
...
SongOTD
2 years, 1 month ago
Is it about need-to-know or least privilege? I was thinking about A.
upvoted 1 times
...
CuteRabbit168
2 years, 1 month ago
Could B be a better answer ? Security and awareness training….
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...