Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CISSP Exam - Topic 1 Question 113 Discussion

Which of the following is considered the FIRST step when designing an internal security control assessment?
C) Create a plan based on a recognized framework of known controls.
A) Create a plan based on recent vulnerability scans of the systems in question.
B) Create a plan based on comprehensive knowledge of known breaches.
D) Create a plan based on reconnaissance of the organization's infrastructure.

ISC2 CISSP Exam - Topic 1 Question 113 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 113
Topic #: 1
[All CISSP Questions]

Which of the following is considered the FIRST step when designing an internal security control assessment?

Show Suggested Answer Hide Answer

Contribute your Thoughts:

0/2000 characters
Mireya
8 hours ago
I prefer D. Knowing the infrastructure first is key.
upvoted 0 times
...
Hollis
6 days ago
I think option C is the best. Frameworks are essential.
upvoted 0 times
...
Elise
11 days ago
C is the standard approach, can't go wrong with that!
upvoted 0 times
...
Dierdre
16 days ago
Wait, is D really a first step? Sounds a bit off to me.
upvoted 0 times
...
Novella
2 months ago
A is a solid choice too, but it feels a bit reactive.
upvoted 0 times
...
Hildred
2 months ago
I disagree, B makes more sense since we learn from past breaches.
upvoted 0 times
...
Toi
2 months ago
I think it's definitely C, frameworks are key!
upvoted 0 times
...
Melinda
3 months ago
I disagree, C is the standard approach in most cases.
upvoted 0 times
...
Marica
3 months ago
Surprised that B is even an option, breaches are so varied!
upvoted 0 times
...
Rose
3 months ago
I’m leaning towards D, you need to know your infrastructure first.
upvoted 0 times
...
Yvette
3 months ago
A seems more practical to me, recent scans are crucial.
upvoted 0 times
...
Minna
3 months ago
I think it’s definitely C, frameworks are key!
upvoted 0 times
...
Anabel
3 months ago
I practiced a question similar to this, and I think reconnaissance of the organization's infrastructure is crucial, but it might not be the very first step.
upvoted 0 times
...
Ellen
4 months ago
I feel like creating a plan based on known breaches could be a good starting point, but it might not cover everything we need to assess.
upvoted 0 times
...
Antonio
4 months ago
I'm not entirely sure, but I remember something about using recent vulnerability scans to inform the assessment. Maybe that's important too?
upvoted 0 times
...
Paola
4 months ago
I think the first step should be based on a recognized framework of known controls, like NIST or ISO. That seems foundational.
upvoted 0 times
...

Save Cancel