712-50 · Question #189
As the CISO for your company you are accountable for the protection of information resources commensurate with:
The correct answer is D. Risk of exposure. Protection of information resources must be proportional to the risk of exposure (D) - this is the foundational principle of risk-based security. A CISO's job is to identify threats, assess likelihood and impact, and allocate controls accordingly. Resources that carry higher…
Question
As the CISO for your company you are accountable for the protection of information resources commensurate with:
Options
- ACustomer demand
- BCost and time to replace
- CInsurability tables
- DRisk of exposure
How the community answered
(57 responses)- A2% (1)
- B5% (3)
- C9% (5)
- D84% (48)
Explanation
Protection of information resources must be proportional to the risk of exposure (D) - this is the foundational principle of risk-based security. A CISO's job is to identify threats, assess likelihood and impact, and allocate controls accordingly. Resources that carry higher risk of exposure warrant stronger, more costly protection; low-risk assets require proportionally less.
Why the distractors fail:
- A (Customer demand) - Security decisions driven by customer preferences rather than actual risk lead to inconsistent, reactive protection that may miss critical exposures.
- B (Cost and time to replace) - Asset replacement cost relates to availability and business continuity, not to how sensitive or exposed the information itself is; a cheap asset can still carry massive breach risk.
- C (Insurability tables) - Insurance helps transfer risk financially but is not the standard by which you determine the level of protection to apply.
Memory tip: Think of the CISO's job as a risk-proportional shield - the bigger the target on an asset (its exposure risk), the thicker the shield. Risk always drives the protection decision, not cost, customer wishes, or insurance tables.
Topics
Community Discussion
No community discussion yet for this question.