nerdexam
Isaca

CISA · Question #551

What is the main objective when implementing security controls within an application?

The correct answer is B. To optimize the level of data protection achieved against cost. The main objective of implementing security controls is to optimize the level of data protection achieved against cost-this reflects the fundamental risk management principle that security investment should be proportional to the value and sensitivity of the asset being protected

Submitted by carlos_mx· Apr 18, 2026Protection of Information Assets

Question

What is the main objective when implementing security controls within an application?

Options

  • ATo optimize user functionality of the application
  • BTo optimize the level of data protection achieved against cost
  • CTo minimize reputational risk to the organization
  • DTo minimize the exposure to the fullest extent possible

How the community answered

(49 responses)
  • A
    2% (1)
  • B
    90% (44)
  • C
    6% (3)
  • D
    2% (1)

Explanation

The main objective of implementing security controls is to optimize the level of data protection achieved against cost-this reflects the fundamental risk management principle that security investment should be proportional to the value and sensitivity of the asset being protected. Option A (user functionality) is a usability goal, not a security objective. Option C (minimizing reputational risk) is a business outcome, not the primary security objective. Option D (minimizing exposure to the fullest extent) ignores cost-benefit trade-offs; perfect security is rarely achievable or economically justified.

Topics

#Security controls#Risk management#Cost-benefit analysis#Application security

Community Discussion

No community discussion yet for this question.

Full CISA Practice