nerdexam
(ISC)2

CISSP · Question #177

What is the BEST first step for determining if the appropriate security controls are in place for protecting data at rest?

The correct answer is B. Conduct a risk assessment. A risk assessment is the best first step for determining if the appropriate security controls are in place for protecting data at rest. A risk assessment involves identifying the assets, threats, vulnerabilities, and impacts related to the data, as well as the likelihood and seve

Submitted by tarun92· Mar 5, 2026Security and Risk Management

Question

What is the BEST first step for determining if the appropriate security controls are in place for protecting data at rest?

Options

  • AIdentify regulatory requirements
  • BConduct a risk assessment
  • CDetermine business drivers
  • DReview the security baseline configuration

How the community answered

(47 responses)
  • A
    2% (1)
  • B
    77% (36)
  • C
    15% (7)
  • D
    6% (3)

Explanation

A risk assessment is the best first step for determining if the appropriate security controls are in place for protecting data at rest. A risk assessment involves identifying the assets, threats, vulnerabilities, and impacts related to the data, as well as the likelihood and severity of potential breaches. Based on the risk assessment, the appropriate security controls can be selected and implemented to mitigate the risks to an acceptable level.

Topics

#risk assessment#data at rest protection#security control implementation#security program management

Community Discussion

No community discussion yet for this question.

Full CISSP Practice