Question 1 of 30
Benchmark analysis indicates that a rapidly growing technology firm is experiencing an increase in security incidents, particularly related to unauthorized data access and malware infections. The IT security team is tasked with developing new security policies and procedures to address these emerging threats. Given the firm\'s limited resources and the need to maintain operational agility, which of the following approaches would be the most effective and professionally responsible for developing these new policies?
Conduct a thorough risk assessment to identify critical assets and high-risk areas, then develop and implement policies and controls that directly address these prioritized risks, allowing for iterative refinement.
Mandate the immediate implementation of the most stringent security controls available across all systems and user groups to ensure comprehensive protection.
Rely solely on the security recommendations provided by the primary cloud service provider to define the organization's security policies.
Prioritize user convenience and ease of access in policy development, deferring detailed security control implementation to a later phase after initial adoption of new systems.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free