nerdexam
(ISC)2(ISC)2

CISSP · Question #376

CISSP Question #376: Real Exam Question with Answer & Explanation

Sign in or unlock CISSP to reveal the answer and full explanation for question #376. The question stem and answer options stay visible for context.

Submitted by andres_qro· Mar 5, 2026Security and Risk Management

Question

Company A is evaluating new software to replace an in-house developed application. During the acquisition process. Company A specified the security retirement, as well as the functional requirements. Company B responded to the acquisition request with their flagship product that runs on an Operating System (OS) that Company A has never used nor evaluated. The flagship product meets all security -and functional requirements as defined by Company A. Based upon Company B's response, what step should Company A take?

Options

  • AMove ahead with the acpjisition process, and purchase the flagship software
  • BConduct a security review of the OS
  • CPerform functionality testing
  • DEnter into contract negotiations ensuring Service Level Agreements (SLA) are established to

Unlock CISSP to see the answer

You've previewed enough free CISSP questions. Unlock CISSP for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Topics

#Software acquisition#Third-party risk#OS security#Due diligence
Full CISSP PracticeBrowse All CISSP Questions