exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 203 discussion

Actual exam question from CompTIA's CS0-002
Question #: 203
Topic #: 1
[All CS0-002 Questions]

A financial institution's business unit plans to deploy a new technology in a manner that violates existing information security standards. Which of the following actions should the Chief Information Security Officer (CISO) take to manage any type of violation?

  • A. Enforce the existing security standards and controls.
  • B. Perform a risk analysis and qualify the risk with legal.
  • C. Perform research and propose a better technology.
  • D. Enforce the standard permits.
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
rphadol
1 year, 7 months ago
Vote for B. agree with @prntscrn23
upvoted 1 times
...
Big_Dre
1 year, 8 months ago
Selected Answer: B
is the best option
upvoted 1 times
...
kiduuu
2 years ago
Selected Answer: B
Option B is the most appropriate action because it enables the CISO to understand the potential risks associated with the deployment of the new technology, assess the impact it could have on the organization, and determine the legal implications of any breaches that may arise. This approach allows the CISO to identify the gaps between the existing security standards and the new technology, and to determine the appropriate course of action to manage any violations.
upvoted 1 times
...
thenewpcgamer
2 years ago
Selected Answer: A
Sorry meant A
upvoted 2 times
...
thenewpcgamer
2 years ago
Selected Answer: B
The business unit is rolling out technology that will violate the companies technology standards.... The CISO should stand his ground and enforce the policies.. thats his job. There is no reason to get legal involved.. this is a conflict within the organization itself.
upvoted 1 times
...
roman1000
2 years, 4 months ago
Selected Answer: B
The International Standards Organization, or ISO, develops standards for businesses around the world so that they may operate using a uniform set of best practices. These standards are not enforceable laws, but companies who choose to follow them stand to gain international credibility from their compliance; standards are set as guidance for best practices but are not enforceable laws, so B.
upvoted 2 times
2Fish
2 years, 1 month ago
Agree with B. This does seem to be the best answer.
upvoted 1 times
2Fish
2 years, 1 month ago
https://www.examtopics.com/discussions/comptia/view/56226-exam-cs0-002-topic-1-question-193-discussion/
upvoted 1 times
...
...
...
prntscrn23
2 years, 5 months ago
Selected Answer: B
I will put my money on B and here's I interpret the scenario: Right off the bat it says "deploy a new technology in a manner that violates existing information security standards." First reaction is "No. Security standards and controls are there for a reason and we will not move forward on this proposal/plan." However in real world scenario, before C-Suite levels and Leaders and Legal (if it involves PIIs) in an organization gives a decision, they will discuss the following: 1. How this "new technology" will benefit the business (functions)? 2. What are the advantages and disadvantages of this "new technology" in terms of business side, the team that will use the technology, maintenance, support, and so on.. 3. What are the possible risks and its severity levels that it can bring to the business and how the team that will support it manage resolve it? and the list goes on. Once those things are discussed, C-Suites and the Leaders will decide if they are going to move forward and explore the new technology or not. ***Let me know your insights..
upvoted 1 times
...
forest111
2 years, 5 months ago
Selected Answer: B
one of CISO duties is performing risk assessments so he can do some analysis and show some examples to legal
upvoted 2 times
iking
2 years, 5 months ago
I would go for B. We are talking about Financial institution which is not part of the company, we cannot enforce our policy when they have their own. We need legal
upvoted 1 times
...
...
Comptia_Secret_Service
2 years, 5 months ago
Selected Answer: A
The answer is in the question itself, "violates existing information security standard", solution? enforce it.
upvoted 2 times
...
Frog_Man
2 years, 5 months ago
A - There could be legal reasons as it might fall under the Statement of Work (SOW)
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago