Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard

A newly appointed Chief Information Security Officer (CISO) is tasked with establishing a unified, organization-wide approach to managing cybersecurity risks. The CISO wants to adopt a set of guidelines and best practices that provide a common language and systematic methodology for identifying, assessing, and responding to cyber threats. Which foundational security concept should the CISO prioritize implementing?

  1. ASecurity awareness training program
  2. BSecurity frameworks
  3. CSecurity operations center (SOC)
  4. DAdvanced persistent threat (APT) intelligence
Show answer & explanation

Correct answer: B. Security frameworks

The CISO needs a 'unified, organization-wide approach' with 'guidelines and best practices' and a 'systematic methodology'. This perfectly describes the purpose of 'security frameworks' like NIST CSF or ISO 27001, which provide the structure for managing security.

Why the other options are wrong

  • A. Awareness training educates employees; it's a component, not the overarching methodology.
  • C. A SOC is an operational unit, not a foundational methodology for overall risk management.
  • D. APT intelligence is a specific type of threat data, not a comprehensive management approach.

Security Frameworks

A structured set of guidelines, best practices, and standards that organizations can use to manage and improve their cybersecurity risk posture and establish a comprehensive security program.

  • Provide a common language and systematic approach to security.
  • Examples include NIST Cybersecurity Framework, ISO 27001, CIS Controls.
  • Help organizations comply with regulations and achieve security objectives.

Memory trick: Frameworks build the foundation for a strong security house.

More Security Concepts questions