CISSP Practice Question
A multinational organization discovers that a critical third-party SaaS provider processes sensitive customer data. During a routine review, the security team learns that the provider does not support MFA for privileged administrative accounts.The organization’s security policy requires MFA for privileged access, but the SaaS contract does not explicitly require the provider to implement it. The business owner argues that replacing the provider would be expensive and could disrupt operations.
What should the security manager do FIRST?
A. Require the provider to implement MFA immediately as a condition of continued service.
B. Perform a risk assessment to determine whether the provider's control gap exceeds the organization's risk appetite.
C. Terminate the provider because it violates the organization's security policy.
D. Negotiate a contractual amendment requiring MFA and periodic compliance audits.
1
2 comments
Hassan Na
5
CISSP Practice Question
CISSP Study Group
skool.com/cybersecurity-study-group
Share resources, get advice, and connect with peers studying cybersecurity. Join our CISSP study group and connect with fellow professionals today!
Leaderboard (30-day)
Powered by