nerdexam
CompTIA

CAS-002 · Question #135

A security engineer is implementing a new solution designed to process e-business transactions and record them in a corporate audit database. The project has multiple technical stakeholders. The…

The correct answer is A. Ensure the process functions in a secure manner from customer input to audit review. As solution owner, the security engineer holds end-to-end responsibility for ensuring the entire e-business process operates securely across all team boundaries.

Integration of Computing, Communications and Business Disciplines

Question

A security engineer is implementing a new solution designed to process e-business transactions and record them in a corporate audit database. The project has multiple technical stakeholders. The database team controls the physical database resources, the internal audit division controls the audit records in the database, the web hosting team is responsible for implementing the website front end and shopping cart application, and the accounting department is responsible for processing the transaction and interfacing with the payment processor. As the solution owner, the security engineer is responsible for ensuring which of the following?

Options

  • AEnsure the process functions in a secure manner from customer input to audit review.
  • BSecurity solutions result in zero additional processing latency.
  • CEnsure the process of storing audit records is in compliance with applicable laws.
  • DWeb transactions are conducted in a secure network channel.

How the community answered

(35 responses)
  • A
    74% (26)
  • B
    6% (2)
  • C
    14% (5)
  • D
    6% (2)

Why each option

As solution owner, the security engineer holds end-to-end responsibility for ensuring the entire e-business process operates securely across all team boundaries.

AEnsure the process functions in a secure manner from customer input to audit review.Correct

A solution owner is accountable for the security of the complete system, not just individual components owned by other teams. This means ensuring security is maintained across every handoff point - from the customer-facing web application through payment processing to final audit record storage - even when separate teams control each layer independently.

BSecurity solutions result in zero additional processing latency.

Zero additional processing latency is an unrealistic and non-security requirement; security controls inherently introduce some overhead and this metric is not within the solution owner's security mandate.

CEnsure the process of storing audit records is in compliance with applicable laws.

Compliance of audit record storage is a narrower responsibility that falls primarily to the internal audit division, not the broader end-to-end scope held by the solution owner.

DWeb transactions are conducted in a secure network channel.

Securing web transaction channels is a single component responsibility belonging to the web hosting team and represents only a fraction of the solution owner's full accountability.

Concept tested: Solution owner end-to-end security accountability across stakeholders

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#solution ownership#e-business security#stakeholder management#audit trail

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice