nerdexam
EC-Council

512-50 · Question #300

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You…

The correct answer is C. Verify that the cost of mitigation is less than the risk. See the full explanation below for the reasoning.

Question

Scenario: You are the CISO and have just completed your first risk assessment for your organization. You find many risks with no security controls, and some risks with inadequate controls. You assign work to your staff to create or adjust existing security controls to ensure they are adequate for risk mitigation needs. You have identified potential solutions for all of your risks that do not have security controls. What is the NEXT step?

Options

  • AGet approval from the board of directors
  • BScreen potential vendor solutions
  • CVerify that the cost of mitigation is less than the risk
  • DCreate a risk metrics for all unmitigated risks

How the community answered

(69 responses)
  • A
    4% (3)
  • B
    12% (8)
  • C
    77% (53)
  • D
    7% (5)

Community Discussion

No community discussion yet for this question.

Full 512-50 Practice