nerdexam
CompTIA

CAS-001 · Question #131

An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security…

The correct answer is C. Classify information types used within the system into levels of confidentiality, integrity, and availability. Classifying information types by Confidentiality, Integrity, and Availability (CIA) is the foundational, repeatable process for establishing a security architecture. By systematically categorizing what data the system handles and assigning CIA sensitivity levels, the architect…

Enterprise Security

Question

An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security architecture?

Options

  • AInspect a previous architectural document.
  • BImplement controls based on the system needs. Perform a risk analysis of the system.
  • CClassify information types used within the system into levels of confidentiality, integrity, and availability.
  • DPerform a risk analysis of the system.

How the community answered

(52 responses)
  • A
    4% (2)
  • B
    15% (8)
  • C
    73% (38)
  • D
    8% (4)

Explanation

Classifying information types by Confidentiality, Integrity, and Availability (CIA) is the foundational, repeatable process for establishing a security architecture. By systematically categorizing what data the system handles and assigning CIA sensitivity levels, the architect can derive consistent, justified, and auditable security requirements and controls across any system. Option A (inspecting a previous document) is not repeatable or generalizable. Option B puts implementation before risk analysis, reversing the correct order. Option D (risk analysis alone) is necessary but incomplete without first understanding the data classifications that drive that analysis.

Topics

#security architecture#information classification#CIA triad#risk analysis

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice