nerdexam
EXIN

ITSM20F · Question #31

What is the objective of the Security Management process?

The correct answer is D. to manage information security effectively within all service activities. Security Management aims to protect all service activities - covering people, processes, and technology across the entire organization - which is why D is correct. Limiting scope to critical services (A), IT staff only (B), or financial administration (C) each represent partial c

Control processes

Question

What is the objective of the Security Management process?

Options

  • Ato manage information security effectively for critical services only
  • Bto manage information security effectively for IT staff
  • Cto manage information security effectively relating to the financial administration of service
  • Dto manage information security effectively within all service activities

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    7% (2)
  • C
    7% (2)
  • D
    83% (25)

Explanation

Security Management aims to protect all service activities - covering people, processes, and technology across the entire organization - which is why D is correct. Limiting scope to critical services (A), IT staff only (B), or financial administration (C) each represent partial coverage, and security gaps arise precisely where scope is narrowed. The ITIL Security Management process is explicitly designed to align with business-wide security requirements, not any single department or service tier.

Memory tip: Think "Security has no exceptions" - if the answer restricts who or what is protected, it's wrong. The word all in option D is the signal that matches the process's universal scope.

Topics

#security management#information security#process objectives#scope of security

Community Discussion

No community discussion yet for this question.

Full ITSM20F Practice