nerdexam
CompTIA

CAS-002 · Question #188

A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security…

The correct answer is C. Introduce an ESA framework. An Enterprise Security Architecture (ESA) framework provides the formalized methodology needed to incorporate business drivers, capabilities, baselines, and reusable patterns for consistent security design.

Integration of Computing, Communications and Business Disciplines

Question

A large financial company has a team of security-focused architects and designers that contribute into broader IT architecture and design solutions. Concerns have been raised due to the security contributions having varying levels of quality and consistency. It has been agreed that a more formalized methodology is needed that can take business drivers, capabilities, baselines, and re usable patterns into account. Which of the following would BEST help to achieve these objectives?

Options

  • AConstruct a library of re-usable security patterns
  • BConstruct a security control library
  • CIntroduce an ESA framework
  • DInclude SRTM in the SDLC

How the community answered

(22 responses)
  • A
    5% (1)
  • B
    23% (5)
  • C
    59% (13)
  • D
    14% (3)

Why each option

An Enterprise Security Architecture (ESA) framework provides the formalized methodology needed to incorporate business drivers, capabilities, baselines, and reusable patterns for consistent security design.

AConstruct a library of re-usable security patterns

A library of reusable security patterns covers only one component of the needed methodology and does not address business driver alignment, capability modeling, or baseline governance.

BConstruct a security control library

A security control library catalogs individual controls but does not provide the architectural methodology needed to translate business requirements into consistent, high-quality security designs.

CIntroduce an ESA frameworkCorrect

An ESA framework establishes a structured, repeatable approach to security architecture that explicitly integrates business drivers, security capability models, configuration baselines, and reusable design patterns into a coherent reference architecture. This formalization ensures that security architects across the team work from the same methodology, directly addressing the quality and consistency gaps identified by the organization.

DInclude SRTM in the SDLC

Including an SRTM (Security Requirements Traceability Matrix) in the SDLC improves requirements tracking within development projects but is not a broad architectural framework addressing the full scope of the problem described.

Concept tested: Enterprise Security Architecture framework for design consistency

Source: https://www.sabsa.org/the-sabsa-framework/

Topics

#enterprise security architecture#ESA framework#security patterns#SABSA

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice