New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

ISC2 CISSP Exam - Topic 5 Question 17 Discussion

Actual exam question for ISC2's CISSP exam
Question #: 17
Topic #: 5
[All CISSP Questions]

When defining a set of security controls to mitigate a risk, which of the following actions MUST occur?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Oretha
4 months ago
Totally agree, evaluating each control is crucial for security!
upvoted 0 times
...
Kris
4 months ago
Surprised to see "evenly divided the risk" as an option, that doesn't make sense!
upvoted 0 times
...
Laticia
4 months ago
I think the control set just needs to adequately mitigate the risk.
upvoted 0 times
...
Alita
4 months ago
I disagree, not every control needs to completely mitigate the risk.
upvoted 0 times
...
Kendra
5 months ago
Each control's effectiveness should definitely be evaluated!
upvoted 0 times
...
Lina
5 months ago
I think we practiced a question similar to this, and it emphasized that the control set should adequately mitigate the risk, which sounds like option C again.
upvoted 0 times
...
Kiley
5 months ago
I'm a bit unsure about this one. I feel like we talked about evaluating controls individually, but I'm not sure if that's a must.
upvoted 0 times
...
Edmond
5 months ago
I remember discussing how not every control needs to completely mitigate the risk, so I think option C might be the right choice.
upvoted 0 times
...
Celia
5 months ago
I vaguely recall something about evenly distributing risk among controls, but that doesn't seem right. I think option D is definitely not the answer.
upvoted 0 times
...
Tracey
5 months ago
This seems like a straightforward question about service-oriented architecture. I'll focus on understanding the key concepts of service composition and recomposition.
upvoted 0 times
...
Lashon
5 months ago
Okay, let me think this through. Quality assurance is about preventing defects, so I'm guessing the answer is either B or C. Conducting a test to prevent defects from reaching customers sounds like a good quality assurance practice.
upvoted 0 times
...
Hobert
5 months ago
Okay, let me think this through step-by-step. I need to focus on the key terms and how they relate to each other.
upvoted 0 times
...

Save Cancel