ISC2 CISSP Practice Question

During a quarterly security review, a financial services company discovers that a legacy payment application cannot support the mandated full-disk encryption control without causing system instability. To maintain service availability, the CISO invokes the organization's documented security exception handling process. Which activity BEST captures the primary purpose of this process?

  • Trigger the incident response plan to contain and eradicate the vulnerability

  • Record unusual events detected by the vulnerability scanner for root-cause analysis

  • Document and track the deviation from policy, assess risk, and obtain approval with compensating controls

  • Compile audit evidence to address compliance findings from external regulators

ISC2 CISSP
Security Assessment and Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot