nerdexam
CompTIA

CAS-001 · Question #483

A security manager has started a new job and has identified that a key application for a new client does not have an accreditation status and is currently not meeting the compliance requirement for…

The correct answer is B. The security manager decides to use the previous SRTM without reviewing the system. Using a previous SRTM without reviewing the current system state presents the most risk because the entire risk assessment is built on potentially obsolete data that may no longer reflect the system's actual security posture.

Research and Analysis

Question

A security manager has started a new job and has identified that a key application for a new client does not have an accreditation status and is currently not meeting the compliance requirement for the contract's SOW. The security manager has competing priorities and wants to resolve this issue quickly with a system determination and risk assessment. Which of the following approaches presents the MOST risk to the security assessment?

Options

  • AThe security manager reviews the system description for the previous accreditation, but does not
  • BThe security manager decides to use the previous SRTM without reviewing the system
  • CThe security manager hires an administrator from the previous contract to complete the
  • DThe security manager does not interview the vendor to determine if the system description is

How the community answered

(38 responses)
  • A
    8% (3)
  • B
    55% (21)
  • C
    24% (9)
  • D
    13% (5)

Why each option

Using a previous SRTM without reviewing the current system state presents the most risk because the entire risk assessment is built on potentially obsolete data that may no longer reflect the system's actual security posture.

AThe security manager reviews the system description for the previous accreditation, but does not

Reviewing the previous accreditation's system description, even if incomplete, still provides a partial baseline reference, making it less risky than relying on an entirely unreviewed traceability matrix.

BThe security manager decides to use the previous SRTM without reviewing the systemCorrect

The Security Requirements Traceability Matrix maps security requirements to system components and controls; relying on a prior SRTM without verifying the current system means the assessment is grounded in data that may be invalid if the system has been modified, upgraded, or reconfigured since the last accreditation. This flaw propagates through the entire assessment, potentially leaving real vulnerabilities unidentified and producing a risk determination that does not reflect the actual environment.

CThe security manager hires an administrator from the previous contract to complete the

Hiring an administrator from the previous contract leverages institutional knowledge about the system's history and configuration, which reduces assessment risk rather than increasing it.

DThe security manager does not interview the vendor to determine if the system description is

Skipping the vendor interview omits one input into the system description but does not invalidate the entire analytical framework the way an unreviewed SRTM does.

Concept tested: Risk of relying on outdated SRTM in security accreditation

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#accreditation#SRTM#risk assessment#compliance

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice