nerdexam
CompTIA

CAS-002 · Question #26

The sales division within a large organization purchased touch screen tablet computers for all 250 sales representatives in an effort to showcase the use of technology to its customers and increase…

The correct answer is C. Work with the business to understand and classify the risk associated with the full lifecycle. Since management has overridden the security manager's objections, the best course is to formally evaluate and document the risk across the entire asset lifecycle-from procurement and deployment through use and eventual disposal. This lifecycle risk analysis identifies threats…

Research and Analysis

Question

The sales division within a large organization purchased touch screen tablet computers for all 250 sales representatives in an effort to showcase the use of technology to its customers and increase productivity. This includes the development of a new product tracking application that works with the new platform. The security manager attempted to stop the deployment because the equipment and application are non-standard and unsupported within the organization. However, upper management decided to continue the deployment. Which of the following provides the BEST method for evaluating the potential threats?

Options

  • AConduct a vulnerability assessment to determine the security posture of the new devices
  • BBenchmark other organization's that already encountered this type of situation and apply all
  • CWork with the business to understand and classify the risk associated with the full lifecycle
  • DDevelop a standard image for the new devices and migrate to a web application to eliminate

How the community answered

(35 responses)
  • A
    14% (5)
  • B
    3% (1)
  • C
    77% (27)
  • D
    6% (2)

Explanation

Since management has overridden the security manager's objections, the best course is to formally evaluate and document the risk across the entire asset lifecycle-from procurement and deployment through use and eventual disposal. This lifecycle risk analysis identifies threats at each stage, helps the business make informed risk decisions, and creates accountability. A vulnerability assessment (A) is a point-in-time technical scan and doesn't capture ongoing lifecycle risks or business context. Benchmarking other organizations (B) may provide useful reference points but doesn't account for this organization's specific environment, data sensitivity, or risk tolerance. Developing a standard image (D) is a remediation action, not an evaluation of potential threats.

Topics

#risk lifecycle management#mobile device security#BYOD#risk classification

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice