SY0-701 · Question #534
A new security regulation was announced that will take effect in the coming year. A company must comply with it to remain in business. Which of the following activities should the company perform…
The correct answer is A. Gap analysis. Gap analysis (A) is the right first step because it compares the company's current security posture against the requirements of the new regulation, revealing exactly what is missing or insufficient before any remediation work begins - you can't close gaps you haven't…
Question
A new security regulation was announced that will take effect in the coming year. A company must comply with it to remain in business. Which of the following activities should the company perform next?
Options
- AGap analysis
- BPolicy review
- CSecurity procedure evaluation
- DThreat scope reduction
How the community answered
(17 responses)- A82% (14)
- B6% (1)
- C12% (2)
Explanation
Gap analysis (A) is the right first step because it compares the company's current security posture against the requirements of the new regulation, revealing exactly what is missing or insufficient before any remediation work begins - you can't close gaps you haven't identified.
Policy review (B) and security procedure evaluation (C) are activities that follow a gap analysis; you review and update policies/procedures to address the specific gaps uncovered, not before you know what those gaps are. Threat scope reduction (D) is a risk management technique focused on minimizing attack surface, which is unrelated to the compliance-mapping task at hand.
Memory tip: Think of it as "measure before you build" - a gap analysis is always the diagnostic step that precedes any compliance or remediation action. Whenever a question involves a new requirement or new standard, the answer is almost always gap analysis first.
Topics
Community Discussion
No community discussion yet for this question.