820-427 · Question #31
You need to evaluate a solution to improve security for access to the company intranet. Which action should be in scope of your work?
The correct answer is D. Ask Finance to provide a list of risks with potential value. Why D is correct: When evaluating a solution, you must first understand the risk landscape - specifically what risks exist and their potential business impact (value). Asking Finance to provide a risk list with potential value directly informs whether the proposed intranet…
Question
You need to evaluate a solution to improve security for access to the company intranet. Which action should be in scope of your work?
Options
- ARead analyst reports and benchmark studies on software products.
- BHire a consultant to assess data center physical security.
- CArrange vendors to conduct virus detection demos for IT and business managers.
- DAsk Finance to provide a list of risks with potential value.
How the community answered
(26 responses)- A4% (1)
- B19% (5)
- C8% (2)
- D69% (18)
Explanation
Why D is correct: When evaluating a solution, you must first understand the risk landscape - specifically what risks exist and their potential business impact (value). Asking Finance to provide a risk list with potential value directly informs whether the proposed intranet security solution addresses the right threats at the right priority, which is the core of a security evaluation.
Why the distractors are wrong:
- A (analyst reports) is research/market analysis, useful for selecting a product but not for evaluating a solution against your company's specific risk profile.
- B (physical data center security) is out of scope - the question concerns intranet access (logical/network security), not physical premises.
- C (vendor demos) is a procurement/sales activity, not an evaluation of your security posture or risk exposure.
Memory tip: Think of evaluation as answering "Does this solution solve our problem?" - you can only answer that if you know what your risks and their financial impact are. Finance owns that data. When in doubt, risk identification with business value always belongs in the evaluation scope.
Topics
Community Discussion
No community discussion yet for this question.