nerdexam
CompTIA

CAS-001 · Question #156

A security administrator wants to verify and improve the security of a business process which is tied to proven company workflow. The security administrator was able to improve security by applying…

The correct answer is B. Conduct a gap analysis and recommend appropriate non-technical mitigating controls, and incorporate. After exhausting all technical controls defined by the current security standard, the next logical step within the administrator's authority is to conduct a gap analysis - identifying the difference between the current security posture and the desired/optimal posture - and then…

Enterprise Security

Question

A security administrator wants to verify and improve the security of a business process which is tied to proven company workflow. The security administrator was able to improve security by applying controls that were defined by the newly released company security standard. Such controls included code improvement, transport encryption, and interface restrictions. Which of the following can the security administrator do to further increase security after having exhausted all the technical controls dictated by the company's security standard?

Options

  • AModify the company standard to account for higher security and meet with upper management for
  • BConduct a gap analysis and recommend appropriate non-technical mitigating controls, and incorporate
  • CConduct a risk analysis on all current controls, and recommend appropriate mechanisms to increase
  • DModify the company policy to account for higher security, adapt the standard accordingly, and implement

How the community answered

(43 responses)
  • A
    2% (1)
  • B
    70% (30)
  • C
    19% (8)
  • D
    9% (4)

Explanation

After exhausting all technical controls defined by the current security standard, the next logical step within the administrator's authority is to conduct a gap analysis - identifying the difference between the current security posture and the desired/optimal posture - and then recommend non-technical (administrative, procedural, or physical) mitigating controls to address residual risks. Option B is correct because it stays within what the administrator can do without requiring policy or standard modification. Non-technical controls can include things like separation of duties, mandatory security awareness training, physical access restrictions, or process controls. Options A and D both require modifying company standards or policies, which is outside the security administrator's typical authority and requires management involvement. Option C (risk analysis only) stops short of recommending additional controls and does not address the gap.

Topics

#gap analysis#compensating controls#security standards#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice