nerdexam
(ISC)2

CISSP · Question #1153

When network management is outsourced to third parties, which of the following is the MOST effective method of protecting critical data assets?

The correct answer is C. Employ strong access controls. When outsourcing network management, strong access controls are the most effective technical safeguard because they directly limit and govern what third parties can access, modify, or exfiltrate from critical systems.

Submitted by luis.pe· Mar 5, 2026Identity and Access Management (IAM)

Question

When network management is outsourced to third parties, which of the following is the MOST effective method of protecting critical data assets?

Options

  • AProvide links to security policies
  • BLog all activities associated with sensitive systems
  • CEmploy strong access controls
  • DConfirm that confidentiality agreements are signed

How the community answered

(39 responses)
  • A
    13% (5)
  • B
    8% (3)
  • C
    54% (21)
  • D
    26% (10)

Why each option

When outsourcing network management, strong access controls are the most effective technical safeguard because they directly limit and govern what third parties can access, modify, or exfiltrate from critical systems.

AProvide links to security policies

Providing links to security policies is an administrative awareness measure that does not technically enforce or restrict third-party access to critical systems.

BLog all activities associated with sensitive systems

Logging all activities is a detective control that identifies incidents after they occur but does not prevent unauthorized access or data exfiltration in the first place.

CEmploy strong access controlsCorrect

Strong access controls-such as role-based access control (RBAC), least privilege, multi-factor authentication, and network segmentation-directly prevent unauthorized access to critical data assets by third parties. These controls enforce boundaries at the technical level, ensuring outsourced administrators can only reach systems and data necessary for their specific tasks. Unlike administrative or detective measures, access controls are proactive and preventive, making them the most effective protection method.

DConfirm that confidentiality agreements are signed

Confidentiality agreements are legal and contractual controls that create accountability but provide no technical enforcement mechanism to prevent a third party from accessing or misusing sensitive data.

Concept tested: Third-party risk management and access control enforcement

Source: https://www.nist.gov/publications/nist-special-publication-800-53-revision-5

Topics

#third-party risk#outsourcing security#access control#data protection

Community Discussion

No community discussion yet for this question.

Full CISSP Practice