Certified Information Systems Security Professional (CISSP) — Question 269

What is considered a compensating control for not having electrical surge protectors installed?

Answer options

Correct answer: B

Explanation

A hot disaster recovery (DR) environment is considered a compensating control because it ensures that operations can continue seamlessly even if there are electrical issues. The other options, while beneficial, do not directly address the lack of surge protection in the same manner as a DR environment does.