The correct answer isCbecause CISOs are primarily focused onreducing business risk, minimizing the attack surface, and ensuring operational continuity.Instead of assuming that breaches will never occur, modern security strategies such asZero TrustandSASEaim to mitigate risks, contain breaches, and protect critical business operations to maintain availability and resilience.
Relevant extracts from official HPE Aruba Networking documentation:
“CISOs prioritize reducing the attack surface and ensuring operational resilience, recognizing that breaches are inevitable.”
“Aruba Zero Trust Security minimizes risk by continuously authenticating and authorizing all users and devices, ensuring least-privilege access.”
“By combining visibility, control, and automated enforcement, Aruba solutions help security leaders maintain business continuity while reducing exposure.”
“Operational continuity and resilience are the top business outcomes CISOs seek, enabled by proactive risk minimization strategies.”
Why the other options are incorrect:
APreferred tools may be useful, but tool choice is not the main business outcome for CISOs—it’s about risk reduction and continuity.
BRestricting access to only the corporate campus is outdated in today’s hybrid and remote-first environments.
DAssuming no breach will occur is unrealistic. Modern security models (Zero Trust, Assume Breach) accept that threats will happen and focus on resilience and minimization.
References (HPE Aruba Networking Solutions / Study Guides):
Aruba ESP Zero Trust Security — Solution Overview
Aruba Security and Risk Mitigation — Technical White Paper
Aruba ClearPass and Client Insights — Product Guide
HPE Aruba Networking Business Outcomes for CISOs — Executive Brief
===========