nerdexam
CompTIA

CAS-002 · Question #666

An administrator is assessing the potential risk impact on an accounting system and categorizes it as follows: Administrative Files = {(Confidentiality, Moderate), (Integrity, Moderate)…

The correct answer is C. {(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}. The aggregate security categorization of a system is determined by applying the high-water mark principle, selecting the highest impact level for each security objective across all information types.

Research and Analysis

Question

An administrator is assessing the potential risk impact on an accounting system and categorizes it as follows:

Administrative Files = {(Confidentiality, Moderate), (Integrity, Moderate), (Availability, Low)} Vendor Information = {(Confidentiality, Moderate), (Integrity, Low), (Availability, Low)} Payroll Data = {(Confidentiality, High), (Integrity, Moderate), (Availability, Low)} Which of the following is the aggregate risk impact on the accounting system?

Options

  • A{(Confidentiality, Moderate), (Integrity, Moderate), (Availability,
  • B{(Confidentiality, High), (Integrity, Low), (Availability, Low)}
  • C{(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}
  • D{(Confidentiality, Moderate), (Integrity, Moderate), (Availability,

How the community answered

(31 responses)
  • A
    6% (2)
  • B
    10% (3)
  • C
    81% (25)
  • D
    3% (1)

Why each option

The aggregate security categorization of a system is determined by applying the high-water mark principle, selecting the highest impact level for each security objective across all information types.

A{(Confidentiality, Moderate), (Integrity, Moderate), (Availability,

Choice A uses Moderate for Confidentiality, which ignores the High impact rating assigned to Payroll Data and violates the high-water mark rule.

B{(Confidentiality, High), (Integrity, Low), (Availability, Low)}

Choice B incorrectly assigns Low to Integrity, when both Administrative Files and Payroll Data independently carry an Integrity rating of Moderate.

C{(Confidentiality, High), (Integrity, Moderate), (Availability, Low)}Correct

NIST FIPS 199 mandates that the overall system security category be set at the highest impact level found among all information types for each objective. Confidentiality takes High from Payroll Data, Integrity takes Moderate (the highest value across Administrative Files and Payroll Data), and Availability remains Low across all three types, yielding the correct aggregate of (High, Moderate, Low).

D{(Confidentiality, Moderate), (Integrity, Moderate), (Availability,

Choice D also uses Moderate for Confidentiality rather than High, failing to apply the high-water mark to the Payroll Data Confidentiality value.

Concept tested: FIPS 199 aggregate security categorization high-water mark

Source: https://csrc.nist.gov/publications/detail/fips/199/final

Topics

#risk assessment#CIA triad#risk aggregation#information classification

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice