CAS-001 · Question #238
An administrator is assessing the potential risk impact on an accounting system and categorizes it as follows: Administrative Files = {(Confidentiality, Moderate), (Integrity, Moderate)…
The correct answer is C. {(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}. Aggregate (system-level) risk impact is determined by taking the highest impact rating for each security category across all data types - a single high-impact dataset elevates the entire system for that category. Reviewing the three datasets: Confidentiality values are…
Question
An administrator is assessing the potential risk impact on an accounting system and categorizes it as follows:
Administrative Files = {(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Low)} Vendor Information = {(Confidentiality, Moderate), (Integrity, Low), (Availability, Low)} Payroll Data = {(Confidentiality, High), (Integrity, Moderate), (Availability, Low)} Which of the following is the aggregate risk impact on the accounting system?
Options
- A{(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Moderate)}
- B{(Confidentiality, High), (Integrity, Low), (Availability, Low)}
- C{(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}
- D{(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Low)}
How the community answered
(17 responses)- A35% (6)
- B18% (3)
- C41% (7)
- D6% (1)
Explanation
Aggregate (system-level) risk impact is determined by taking the highest impact rating for each security category across all data types - a single high-impact dataset elevates the entire system for that category. Reviewing the three datasets: Confidentiality values are Moderate, Moderate, and High → aggregate is High. Integrity values are Moderate, Low, and Moderate → aggregate is Moderate. Availability values are Low, Low, and Low → aggregate is Low. This yields (Confidentiality: High, Integrity: Moderate, Availability: Low), which is answer C. This approach follows NIST FIPS 199 guidance, which states that the system's security category for each objective is the maximum value seen across all information types processed by the system.
Topics
Community Discussion
No community discussion yet for this question.