CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 390


The Chief Information Security Officer (CISO) of a large financial institution is responsible for implementing the security controls to protect the confidentiality and integrity of the organization’s Information Systems. Which of the controls below is prioritized FIRST?

Show Answer
Correct Answer: C

In order to protect the confidentiality and integrity of an organization’s Information Systems, encryption of data in transit and data at rest should be prioritized first. Encryption is a fundamental security measure that ensures that the data remains confidential and is protected from unauthorized access both while it is stored and while it is being transmitted. This creates a secure foundation upon which other controls such as firewalls, WAF, HTTPS, and IPS can be layered.

Discussion

6 comments
Sign in to comment
MarkSunOption: C
Mar 31, 2023

Agree with C

HughJassoleOption: D
Jun 9, 2023

Encryption only protects confidentiality; hashing protects integrity so it can't be C. D does seem the best answer.

gjimenezfOption: B
Feb 1, 2024

WAF for integrity and HTTPS for confidentiality

[Removed]Option: D
Apr 5, 2023

I like D. I think C is too much focussed on the data and not on the systems.

jackdryan
May 14, 2023

C is correct

lxm28Option: C
Jun 10, 2023

This is because encryption provides an additional layer of protection to sensitive data, making it more difficult for attackers to access or steal. Firewall, WAF, HTTPS, and IPS are also important security controls, but encryption should be prioritized first to ensure the confidentiality and integrity of the organization's information systems.

klarakOption: B
May 6, 2024

This is a classic CISSP test of semantics, imo. The answer that correlates to the question is WAF and HTTPS. You have to pay attention to the solution that fits the exact question.