exam questions

Exam CISSP All Questions

View all questions & answers for the CISSP exam

Exam CISSP topic 1 question 343 discussion

Actual exam question from ISC's CISSP
Question #: 343
Topic #: 1
[All CISSP Questions]

Which is the PRIMARY mechanism for providing the workforce with the information needed to protect an agency's vital information resources?

  • A. Implementation of access provisioning process for coordinating the creation of user accounts
  • B. Incorporating security awareness and training as part of the overall information security program
  • C. An information technology (IT) security policy to preserve the confidentiality, integrity, and availability of systems
  • D. Execution of periodic security and privacy assessments to the organization
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
WiDeBarulho
Highly Voted 3 years, 1 month ago
Selected Answer: B
Security awareness and training will give you CIA (option "C"). This training will/shall also cover the concepts of need-to-know and least privilege (option "A"). Therefore option "B" is the most appropriate.
upvoted 12 times
jackdryan
2 years, 6 months ago
B is correct
upvoted 1 times
...
...
Jay327
Highly Voted 3 years ago
Selected Answer: C
I vote C "PRIMARY mechanism" Policy comes first and will include awareness and training program? Think like a manager :)
upvoted 7 times
oudmaster
2 years, 11 months ago
I agree with you. Security Policy can include many points other than user training, and it should provide enough/complete security to protect vital information assets.
upvoted 3 times
...
ap0ls
1 year, 8 months ago
Agree. Go with the more general or broader answer
upvoted 1 times
...
eboehm
1 year, 7 months ago
did you even read the question? This is one of those questions that will get you in trouble by auto selecting an answer just cuz it has a policy in it. For one thing, this states an information technology policy. That tends to not be people/process specific. Secondly, yes there would be a policy in place. BUT a policy is not the way you PROVIDE users with the required information as the question asks
upvoted 3 times
...
...
Trap_D0_r
Most Recent 3 days, 3 hours ago
Selected Answer: B
Yet another godawful phrasing here, but the key is "equip the workforce." You can ask users to sign and agree to a EULA all day, doesn't mean they read it, doesn't mean they know not to go on Facebook if it isn't explicitly blocked. Likewise an IT policy won't really help the "workforce" (at large) be aware of and avoid Phishing/Vishing/Malicious Links etc etc. Terrible TERRIBLE question, but I'd have to say B.
upvoted 1 times
...
a_kto_to
6 months, 4 weeks ago
Selected Answer: B
The PRIMARY mechanism to equip the workforce with the knowledge to protect an organization’s vital information resources is through security awareness and training. This ensures: Employees understand policies and how to apply them. Staff are aware of current threats and social engineering tactics. Personnel know how to respond to incidents or anomalies.
upvoted 1 times
...
BigITGuy
7 months, 4 weeks ago
Selected Answer: B
Not C. IT security policy defines rules and principles but alone does not provide active education or ensure that employees understand and can apply these rules.
upvoted 1 times
...
8e1c45b
1 year, 4 months ago
Selected Answer: B
vote for b
upvoted 1 times
...
YesPlease
1 year, 11 months ago
Selected Answer: B
Answer B) Incorporating security awareness and training as part of the overall information security program Answer B includes C since it references an "overall information security program". C does not need to contain anything about end user training.
upvoted 1 times
...
isaac592
2 years, 1 month ago
Selected Answer: B
B - "providing the workforce"
upvoted 3 times
isaac592
2 years, 1 month ago
Also, is states it verbatim in NIST SP800 Ch4: "Establishing and maintaining a robust and relevant information security awareness and training program as part of the overall information security program is the primary conduit for providing the workforce with the information and tools needed to protect an agency’s vital information resources."
upvoted 5 times
...
...
BoyBastos
2 years, 2 months ago
Selected Answer: B
B. Incorporating security awareness and training as part of the overall information security program Incorporating security awareness and training as part of the overall information security program is the primary mechanism for providing the workforce with the information needed to protect an agency's vital information resources. Educating employees and users about security risks, best practices, policies, and procedures helps them understand their roles and responsibilities in safeguarding information resources. While the other options (implementation of access provisioning process, IT security policy, periodic security assessments) are important components of an information security program, security awareness and training play a critical role in ensuring that the workforce is informed and capable of protecting information resources effectively.
upvoted 3 times
...
dark7ness
2 years, 4 months ago
Selected Answer: B
Security awareness is essential
upvoted 1 times
...
HughJassole
2 years, 5 months ago
B. "providing the workforce with the information" sounds like training of employees, hence B is the only match. C wouldn't work because it doesn't train and it is too specific. At my CISSP class the instructor cautioned against too specific of an answer, the strategy is to go with the most comprehensive since CISSP is about high level, not the details.
upvoted 1 times
...
JohnyDal
2 years, 9 months ago
Selected Answer: C
Think like a manager.....policy includes A,B,D....so C is the all-encompassing best managerial answer
upvoted 3 times
...
Dee83
2 years, 10 months ago
B. Incorporating security awareness and training as part of the overall information security program.
upvoted 1 times
...
DJOEK
2 years, 10 months ago
Selected Answer: B
keyword "Workforce" should be correct answer B
upvoted 1 times
...
IXone
3 years ago
Selected Answer: B
keyword "Workforce" should be correct answer B
upvoted 1 times
...
pingundas
3 years, 1 month ago
Policies are information with instructions (must/must not). C seems to be right to me
upvoted 2 times
...
franbarpro
3 years, 1 month ago
The questions says "providing the workforce with the information needed" - That sounds like training to me.
upvoted 5 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...