CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 348


An organization outgrew its internal data center and is evaluating third-party hosting facilities. In this evaluation, which of the following is a PRIMARY factor for selection?

Show Answer
Correct Answer: A

When an organization evaluates third-party hosting facilities, the primary factor for selection should be the facility's ability to provide an acceptable level of risk. This encompasses evaluating the security measures in place, such as physical access controls, network security, and incident response capabilities, ensuring that the facility meets the organization's overall security requirements and operational standards. While cost-effectiveness, disaster recovery services, and physical access protection measures are important, they fall under the broader category of assessing the facility's risk profile. Cost alone should not compromise the organization's security posture.

Discussion

19 comments
Sign in to comment
ItsBananass
Sep 20, 2022

I choose "A", The risk over cost.

jackdryan
May 14, 2023

A is correct

sec_007Option: D
Oct 18, 2022

The benefits of DCO may include reduced operational costs, more efficient use of infrastructure, and access to more server, storage or computing capacity on demand. The risks include lack of control over security and disaster recovery, lack of flexibility, problems with SLA fulfillment and vendor lock-in.

shmoeee
Nov 22, 2023

I say D...as a Manager, first thing I would look at is the budget, then consider the best options. The facility with the acceptable level of risk may be outside of the company's budget.

franbarpro
Oct 26, 2022

As I think like a manager I agree with "D"

JamatiOption: A
Nov 13, 2022

B and C are all covered under A

PeepoKOption: D
Dec 5, 2022

Since the organization outgrew the internal data center, it's looking for a cheaper solution for higher volumes of data. A is not the primary factor.

oudmaster
Dec 9, 2022

There are shared responsibilities between the customer and the Hosting providers. Hosting provider is not responsible to mitigate the customers' systems risk. This is the customer responsibility. And cost-effective does not mean no security. So I elect D.

DJOEKOption: A
Jan 12, 2023

A. Facility provides an acceptable level of risk is the PRIMARY factor for selection according to cissp. This includes evaluating the security measures in place at the facility, such as physical access controls, network security, and incident response capabilities, to ensure that the facility meets the organization's security requirements and provides an acceptable level of risk for the organization's data and operations. Other factors, such as disaster recovery services, physical access protection measures and cost-effectiveness may also be considered but the primary concern is ensuring that the facility provides an acceptable level of risk.

BertoOption: A
Feb 14, 2023

A - If the business simply can't afford it, its not a possibility

Skittle4710Option: A
Jun 10, 2024

A for the test. D for real life.

BP_lobsterOption: A
Dec 1, 2022

Thinking like a CISO. B, C & D are all redundant if the facility does not provide an acceptable level of risk. I.e. You wouldn't take on unacceptable levels of risk to have DR, Physical access protection or to save money.

Mann0302
Dec 8, 2022

Think like a Manager and get a more cost-effective solution with much quality.

eddievonbahnhofOption: A
Dec 9, 2022

I think of cost-benefit analysis contra cost-efficient. Meanwhile cost-efficient is pure about money, cost-benefit covers the balance between security, added value and cost. If i would prioritize cost before security, then i probably make a risk analysis and realize that OPEX/CAPEX of security controls will outpaces the price of more expensive but much safer hosting facility.

Rollingalx
Feb 20, 2023

I vote for A. A facility that is cost-effective or has strong DR services may not necessarily provide an acceptable level of risk.

Tygrond87Option: A
May 10, 2023

Price is part of a risk assesment

041ba31
May 20, 2024

I'm going with D as it focuses on the principle "most bang for my buck".

Dtony66Option: D
Aug 15, 2024

The answer D says it is a "cost" effective solution. Hence it is a solution.

imatherOption: A
Jan 9, 2025

Too little information to make a good decision. A makes the most sense in terms of risk management. D would make sense if we knew what defined cost effective. Is it taking into account primary and secondary cost, cost in terms of cost-benefit analysis, or just the price?

BigITGuyOption: A
Mar 31, 2025

Key word is "PRIMARY". Cost should not drive decisions.