nerdexam
CompTIA

CAS-002 · Question #136

A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers…

The correct answer is B. A definitive plan of action and milestones which lays out resolutions to all vulnerabilities. Before deploying a system with known vulnerabilities, the risk director must require a Plan of Action and Milestones (POA&M) that formally commits to resolving each identified vulnerability.

Enterprise Security

Question

A newly-appointed risk management director for the IT department at Company XYZ, a major pharmaceutical manufacturer, needs to conduct a risk analysis regarding a new system which the developers plan to bring on-line in three weeks. The director begins by reviewing the thorough and well-written report from the independent contractor who performed a security assessment of the system. The report details what seem to be a manageable volume of infrequently exploited security vulnerabilities. The director decides to implement continuous monitoring and other security controls to mitigate the impact of the vulnerabilities. Which of the following should the director require from the developers before agreeing to deploy the system?

Options

  • AAn incident response plan which guarantees response by tier two support within 15 minutes
  • BA definitive plan of action and milestones which lays out resolutions to all vulnerabilities
  • CBusiness insurance to transfer all risk from the company shareholders to the insurance
  • DA prudent plan of action which details how to decommission the system within 90 days of

How the community answered

(42 responses)
  • A
    7% (3)
  • B
    57% (24)
  • C
    24% (10)
  • D
    12% (5)

Why each option

Before deploying a system with known vulnerabilities, the risk director must require a Plan of Action and Milestones (POA&M) that formally commits to resolving each identified vulnerability.

AAn incident response plan which guarantees response by tier two support within 15 minutes

A rapid incident response time guarantee addresses reaction speed after a breach but does not reduce the attack surface created by unmitigated vulnerabilities before the system goes live.

BA definitive plan of action and milestones which lays out resolutions to all vulnerabilitiesCorrect

A POA&M is the formal risk management document that records each identified vulnerability alongside the planned remediation action, responsible owner, and target completion date. Requiring a POA&M before deployment ensures all vulnerabilities are tracked with accountable resolution timelines, which is standard practice under frameworks such as NIST RMF and is necessary for authorizing operation of a system with residual risk.

CBusiness insurance to transfer all risk from the company shareholders to the insurance

Business insurance transfers financial risk to an insurer but does not mitigate the technical vulnerabilities or reduce the probability or impact of a successful exploit.

DA prudent plan of action which details how to decommission the system within 90 days of

Planning to decommission the system within 90 days assumes failure rather than mitigating vulnerabilities - it is not an acceptable risk treatment for a system about to be deployed.

Concept tested: Plan of Action and Milestones for pre-deployment vulnerability management

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#risk management#plan of action and milestones#vulnerability assessment#continuous monitoring

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice