nerdexam
CompTIA

CAS-001 · Question #238

An administrator is assessing the potential risk impact on an accounting system and categorizes it as follows: Administrative Files = {(Confidentiality, Moderate), (Integrity, Moderate)…

The correct answer is C. {(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}. Aggregate (system-level) risk impact is determined by taking the highest impact rating for each security category across all data types - a single high-impact dataset elevates the entire system for that category. Reviewing the three datasets: Confidentiality values are…

Research and Analysis

Question

An administrator is assessing the potential risk impact on an accounting system and categorizes it as follows:

Administrative Files = {(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Low)} Vendor Information = {(Confidentiality, Moderate), (Integrity, Low), (Availability, Low)} Payroll Data = {(Confidentiality, High), (Integrity, Moderate), (Availability, Low)} Which of the following is the aggregate risk impact on the accounting system?

Options

  • A{(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Moderate)}
  • B{(Confidentiality, High), (Integrity, Low), (Availability, Low)}
  • C{(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}
  • D{(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Low)}

How the community answered

(17 responses)
  • A
    35% (6)
  • B
    18% (3)
  • C
    41% (7)
  • D
    6% (1)

Explanation

Aggregate (system-level) risk impact is determined by taking the highest impact rating for each security category across all data types - a single high-impact dataset elevates the entire system for that category. Reviewing the three datasets: Confidentiality values are Moderate, Moderate, and High → aggregate is High. Integrity values are Moderate, Low, and Moderate → aggregate is Moderate. Availability values are Low, Low, and Low → aggregate is Low. This yields (Confidentiality: High, Integrity: Moderate, Availability: Low), which is answer C. This approach follows NIST FIPS 199 guidance, which states that the system's security category for each objective is the maximum value seen across all information types processed by the system.

Topics

#risk assessment#CIA triad#data classification#aggregate risk

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice