nerdexam
CompTIA

CAS-002 · Question #337

A security manager has started a new job and has identified that a key application for a new client does not have an accreditation status and is currently not meeting the compliance requirement for…

The correct answer is B. The security manager decides to use the previous SRTM without reviewing the system. Using a previous SRTM without reviewing the current system state presents the highest risk because outdated security documentation may not reflect system changes, new vulnerabilities, or configuration drift.

Research and Analysis

Question

A security manager has started a new job and has identified that a key application for a new client does not have an accreditation status and is currently not meeting the compliance requirement for the contract's SOW. The security manager has competing priorities and wants to resolve this issue quickly with a system determination and risk assessment. Which of the following approaches presents the MOST risk to the security assessment?

Options

  • AThe security manager reviews the system description for the previous accreditation, but
  • BThe security manager decides to use the previous SRTM without reviewing the system
  • CThe security manager hires an administrator from the previous contract to complete the
  • DThe security manager does not interview the vendor to determine if the system description

How the community answered

(40 responses)
  • A
    15% (6)
  • B
    43% (17)
  • C
    8% (3)
  • D
    35% (14)

Why each option

Using a previous SRTM without reviewing the current system state presents the highest risk because outdated security documentation may not reflect system changes, new vulnerabilities, or configuration drift.

AThe security manager reviews the system description for the previous accreditation, but

Reviewing a previous system description provides a useful historical baseline, which reduces rather than maximizes risk compared to using entirely unreviewed artifacts.

BThe security manager decides to use the previous SRTM without reviewing the systemCorrect

Using a previous Security Requirements Traceability Matrix (SRTM) without reviewing the current system introduces the highest risk because system components, configurations, and threats may have changed since the prior accreditation. The SRTM maps security requirements to controls, and if the current system differs from the documented state, critical coverage gaps will be missed entirely. Proceeding with an assessment based on stale traceability data undermines the integrity of the entire risk assessment and could result in accepting unknown residual risks.

CThe security manager hires an administrator from the previous contract to complete the

Hiring an administrator with firsthand knowledge of the previous contract can improve accuracy and reduce risk by leveraging institutional knowledge of the system's history.

DThe security manager does not interview the vendor to determine if the system description

Not interviewing the vendor is a gap in due diligence but is less risky than proceeding with an unreviewed SRTM that may be entirely outdated and inapplicable.

Concept tested: Risk of using outdated SRTM in security accreditation

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#security accreditation#SRTM#risk assessment methodology#compliance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice