nerdexam
(ISC)2

SSCP · Question #1243

___________________ is ultimately responsible for security and privacy violations.

The correct answer is C. CIO / CEO. Ultimately, the CIO or CEO holds the executive responsibility for an organization's overall security and privacy posture and any resulting violations.

Submitted by ashley.k· Apr 18, 2026Security Concepts and Practices

Question

___________________ is ultimately responsible for security and privacy violations.

Options

  • APerson committing the violation
  • BSecurity Officer
  • CCIO / CEO
  • DOS Software

How the community answered

(34 responses)
  • B
    6% (2)
  • C
    91% (31)
  • D
    3% (1)

Why each option

Ultimately, the CIO or CEO holds the executive responsibility for an organization's overall security and privacy posture and any resulting violations.

APerson committing the violation

While the person committing the violation is directly culpable for their actions, the ultimate organizational responsibility for preventing such violations through policy, training, and controls lies with senior management.

BSecurity Officer

A Security Officer is responsible for implementing and managing security policies and systems, but they report to and are guided by the executive leadership, who hold ultimate responsibility.

CCIO / CEOCorrect

The CIO (Chief Information Officer) or CEO (Chief Executive Officer) bears ultimate executive responsibility for an organization's security and privacy posture, as they are accountable for setting strategic direction, allocating resources, and ensuring compliance, even if day-to-day operations are delegated.

DOS Software

OS Software provides security features and controls, but it is a tool; the responsibility for its proper configuration, maintenance, and adherence to security policies lies with the organization's leadership.

Concept tested: Organizational security responsibility

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/top-10-security-best-practices

Topics

#Organizational responsibility#Security governance#Accountability#Senior management

Community Discussion

No community discussion yet for this question.

Full SSCP Practice