300-220 · Question #133
A key aspect of recommending attack remediation strategies is:
The correct answer is A. Ensuring they are the least disruptive to business operations. Recommending attack remediation strategies must always balance security effectiveness with real-world business constraints - a fix that cripples operations may cause more harm than the original vulnerability. Option A is correct because security professionals serve the…
Question
A key aspect of recommending attack remediation strategies is:
Options
- AEnsuring they are the least disruptive to business operations
- BMaking them as complex as possible
- CFocusing solely on external threats
- DIgnoring the cost implications
How the community answered
(38 responses)- A87% (33)
- B8% (3)
- C3% (1)
- D3% (1)
Explanation
Recommending attack remediation strategies must always balance security effectiveness with real-world business constraints - a fix that cripples operations may cause more harm than the original vulnerability. Option A is correct because security professionals serve the organization, and remediation that unnecessarily disrupts workflows, revenue, or critical services will be rejected or poorly implemented, leaving the organization exposed anyway.
Why the distractors are wrong:
- B - Complexity is a liability, not a virtue; simpler remediations are easier to implement correctly and maintain.
- C - Internal threats (insider threats, misconfigured systems, lateral movement) are equally critical and often more damaging than external ones.
- D - Cost is a primary factor in every security decision; ignoring it produces recommendations that organizations cannot or will not fund.
Memory tip: Think of remediation advice like a doctor's prescription - the best treatment is one the patient will actually follow. A cure that shuts down the patient isn't a cure.
Topics
Community Discussion
No community discussion yet for this question.