CISA · Question #551
What is the main objective when implementing security controls within an application?
The correct answer is B. To optimize the level of data protection achieved against cost. The main objective of implementing security controls is to optimize the level of data protection achieved against cost-this reflects the fundamental risk management principle that security investment should be proportional to the value and sensitivity of the asset being protected
Question
What is the main objective when implementing security controls within an application?
Options
- ATo optimize user functionality of the application
- BTo optimize the level of data protection achieved against cost
- CTo minimize reputational risk to the organization
- DTo minimize the exposure to the fullest extent possible
How the community answered
(49 responses)- A2% (1)
- B90% (44)
- C6% (3)
- D2% (1)
Explanation
The main objective of implementing security controls is to optimize the level of data protection achieved against cost-this reflects the fundamental risk management principle that security investment should be proportional to the value and sensitivity of the asset being protected. Option A (user functionality) is a usability goal, not a security objective. Option C (minimizing reputational risk) is a business outcome, not the primary security objective. Option D (minimizing exposure to the fullest extent) ignores cost-benefit trade-offs; perfect security is rarely achievable or economically justified.
Topics
Community Discussion
No community discussion yet for this question.