nerdexam
CompTIA

CAS-002 · Question #275

Company XYZ has employed a consultant to perform a controls assessment of the HR system, backend business operations, and the SCADA system used in the factory. Which of the following correctly…

The correct answer is B. Avoid, transfer, mitigate, and accept. The four standard risk treatment options used in security controls assessments are avoid, transfer, mitigate, and accept.

Integration of Computing, Communications and Business Disciplines

Question

Company XYZ has employed a consultant to perform a controls assessment of the HR system, backend business operations, and the SCADA system used in the factory. Which of the following correctly states the risk management options that the consultant should use during the assessment?

Options

  • ARisk reduction, risk sharing, risk retention, and risk acceptance.
  • BAvoid, transfer, mitigate, and accept.
  • CRisk likelihood, asset value, and threat level.
  • DCalculate risk by determining technical likelihood and potential business impact.

How the community answered

(29 responses)
  • A
    3% (1)
  • B
    93% (27)
  • D
    3% (1)

Why each option

The four standard risk treatment options used in security controls assessments are avoid, transfer, mitigate, and accept.

ARisk reduction, risk sharing, risk retention, and risk acceptance.

This option mixes inconsistent terminology from different frameworks and does not represent the standard four-option risk treatment taxonomy used in formal controls assessments.

BAvoid, transfer, mitigate, and accept.Correct

Avoid, transfer, mitigate, and accept are the four universally recognized risk response options codified in frameworks such as NIST SP 800-30 and ISO 31000, and they represent the complete decision set a consultant applies when evaluating each identified risk during a controls assessment. Each option maps directly to a specific management action - eliminating the risk source, shifting liability, reducing likelihood or impact, or consciously accepting exposure. These are the correct and complete options the consultant should use across the HR, business operations, and SCADA assessments.

CRisk likelihood, asset value, and threat level.

Risk likelihood, asset value, and threat level are inputs used during the risk analysis phase to calculate risk scores, not the response options used to manage identified risks.

DCalculate risk by determining technical likelihood and potential business impact.

Calculating risk via technical likelihood and business impact describes the risk quantification methodology, not the set of management decisions available after risk has been assessed.

Concept tested: Four standard risk treatment response options

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#risk management#risk treatment#controls assessment#SCADA

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice