Certified Information Systems Security Professional CISSP · Free Practice Question Hard

Question 58

During a vendor security audit, you find evidence that the vendor is violating data protection policies by improperly storing customer credit card data. The vendor offers you a substantial financial incentive to overlook the issue. What is your MOST ethical response?
  • A Confront the vendor privately and give them time to correct the issue without reporting it.
  • B Reject the payment and document the violation in your audit report as required.
  • C Accept the payment and keep silent since reporting the issue may disrupt business operations.
  • D Accept the payment but later report the issue anonymously to protect yourself.
Reveal correct answer

Correct answer: B

Explanation

OBJ. 1.1 - Ethical security professionals must act with integrity and transparency. Accepting a bribe compromises professional integrity and violates ethical standards. Reporting the issue anonymously lacks accountability, and allowing the vendor to fix the problem without documentation can lead to recurring violations. The correct action is to reject the bribe and document the issue in the audit report, ensuring regulatory compliance and accountability. For support or reporting issues, include Question ID: 67d89e533285ff8c3c28204d in your ticket. Thank you.

Discussion

Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.

You must be logged in to post a comment.

Preparing For

Your Certification?

255+ certifications
Detailed explanations
Free PDF samples

Has All The Questions You Need