Security Assessment and Testing Question #94

After theoretical vulnerability reports failed to secure a higher security budget from the CEO, what is the best next step to demonstrate risk?

A. Schedule a meeting with the Chief Privacy Officer to better inform them of the risks.
B. Call a Subject Matter Expert (SME) to perform a more detailed quantitative Risk Assessment.
C. Escalate the problem to the Chief Information Officer (CIO) for budgetary support.
D. Plan a penetration test and present the CEO with detailed, tangible results of successful exploits.
Domain Concept: Security Assessment and Testing

This scenario evaluates management-level decision making in Security Assessment and Testing. In CISSP exam scenarios, evaluate answers through executive governance, risk assessment, life safety, and due diligence before implementing technical controls.

💡 View the Answer & Detailed Explanation

The correct answer to this scenario-based question requires an understanding of the CISSP Managerial Mindset. Register to view our in-depth explanation and access 1100+ adaptive questions completely free.

Fuel the Mission ☕

Keep the vault updated and the servers running.

$
Secure Payment via PayPal

Verified Excellence

Spread the Word

If you like us, share us with your peers.

Scroll to Top