nerdexam
CompTIA

CAS-002 · Question #196

An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security…

The correct answer is C. Classify information types used within the system into levels of confidentiality, integrity, and. A repeatable security architecture process begins with classifying information by CIA categories, which systematically drives all downstream risk analysis and control selection.

Enterprise Security

Question

An architect has been engaged to write the security viewpoint of a new initiative. Which of the following BEST describes a repeatable process that can be used for establishing the security architecture?

Options

  • AInspect a previous architectural document.
  • BImplement controls based on the system needs. Perform a risk analysis of the system.
  • CClassify information types used within the system into levels of confidentiality, integrity, and
  • DPerform a risk analysis of the system.

How the community answered

(22 responses)
  • A
    9% (2)
  • B
    5% (1)
  • C
    82% (18)
  • D
    5% (1)

Why each option

A repeatable security architecture process begins with classifying information by CIA categories, which systematically drives all downstream risk analysis and control selection.

AInspect a previous architectural document.

Reviewing a previous architectural document is not a repeatable or generalizable process - it depends on the existence and relevance of prior documentation and may not apply to a new initiative.

BImplement controls based on the system needs. Perform a risk analysis of the system.

Implementing controls before performing risk analysis reverses the correct order - controls must be selected based on identified risks, not the other way around.

CClassify information types used within the system into levels of confidentiality, integrity, andCorrect

Classifying information types into confidentiality, integrity, and availability levels (as described in NIST SP 800-60 and FIPS 199) is the foundational, repeatable first step in security architecture - it provides a consistent baseline that drives risk analysis and control selection for any system, making the entire process reproducible across different projects and initiatives.

DPerform a risk analysis of the system.

Performing risk analysis without first classifying information types lacks the foundational impact-level data needed to assess risk meaningfully, making the process incomplete and less repeatable.

Concept tested: Information classification as foundation of repeatable security architecture

Source: https://csrc.nist.gov/publications/detail/sp/800-160/vol-1/rev-1/final

Topics

#security architecture#information classification#risk analysis#CIA triad

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice