nerdexam
CompTIA

CAS-001 · Question #178

A security engineer is implementing a new solution designed to process e-business transactions and record them in a corporate audit database. The project has multiple technical stakeholders. The…

The correct answer is A. Ensure the process functions in a secure manner from customer input to audit review. As the solution owner, the security engineer is responsible for the security of the entire end-to-end process - not just one component. With four separate teams each owning a different piece (database, audit records, web front end, payment processing), no single team has…

Integration of Computing, Communications and Business Disciplines

Question

A security engineer is implementing a new solution designed to process e-business transactions and record them in a corporate audit database. The project has multiple technical stakeholders. The database team controls the physical database resources, the internal audit division controls the audit records in the database, the web hosting team is responsible for implementing the website front end and shopping cart application, and the accounting department is responsible for processing the transaction and interfacing with the payment processor. As the solution owner, the security engineer is responsible for ensuring which of the following?

Options

  • AEnsure the process functions in a secure manner from customer input to audit review.
  • BSecurity solutions result in zero additional processing latency.
  • CEnsure the process of storing audit records is in compliance with applicable laws.
  • DWeb transactions are conducted in a secure network channel.

How the community answered

(38 responses)
  • A
    82% (31)
  • B
    5% (2)
  • C
    3% (1)
  • D
    11% (4)

Explanation

As the solution owner, the security engineer is responsible for the security of the entire end-to-end process - not just one component. With four separate teams each owning a different piece (database, audit records, web front end, payment processing), no single team has visibility across the whole chain. The solution owner's job is to ensure that the complete workflow - from the moment a customer enters data through to when it appears in the audit database - functions securely at every handoff and integration point. Option B (zero additional latency) is an unrealistic operational constraint, not a security responsibility. Option C (compliance of audit record storage) is a subset responsibility belonging to the internal audit division, not the overall solution owner. Option D (secure web transactions) is a subset responsibility of the web hosting team. Only Option A captures the holistic, cross-team security ownership role of the solution owner.

Topics

#solution ownership#security architecture#audit#stakeholder management

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice