nerdexam
CompTIA

CAS-002 · Question #835

An IT auditor is reviewing the data classification for a sensitive system. The company has classified the data stored in the sensitive system according to the following matrix: DATA…

The correct answer is C. HIGH, HIGH, HIGH. When aggregating data classifications across multiple data types, the highest classification value in each category must be used - the high water mark principle - not an average.

Enterprise Security

Question

An IT auditor is reviewing the data classification for a sensitive system. The company has classified the data stored in the sensitive system according to the following matrix:

DATA TYPECONFIDENTIALITYINTEGRITYAVAILABILITY ----------------------------------------------------------------------- FinancialHIGHHIGHLOW Client nameMEDIUMMEDIUMHIGH Client addressLOWMEDIUMLOW ----------------------------------------------------------------------- AGGREGATEMEDIUMMEDIUMMEDIUM The auditor is advising the company to review the aggregate score and submit it to senior management. Which of the following should be the revised aggregate score?

Options

  • AHIGH, MEDIUM, LOW
  • BMEDIUM, MEDIUM, LOW
  • CHIGH, HIGH, HIGH
  • DMEDIUM, MEDIUM, MEDIUM

How the community answered

(61 responses)
  • A
    15% (9)
  • B
    8% (5)
  • C
    49% (30)
  • D
    28% (17)

Why each option

When aggregating data classifications across multiple data types, the highest classification value in each category must be used - the high water mark principle - not an average.

AHIGH, MEDIUM, LOW

HIGH, MEDIUM, LOW correctly identifies confidentiality as HIGH but incorrectly selects a middle value for integrity and the lowest value for availability instead of taking the highest across all data types.

BMEDIUM, MEDIUM, LOW

MEDIUM, MEDIUM, LOW ignores that Financial data carries HIGH confidentiality and HIGH integrity ratings, and that Client name carries a HIGH availability rating.

CHIGH, HIGH, HIGHCorrect

The high water mark principle requires that the aggregate classification reflect the most restrictive (highest) value present in each CIA category across all data types. Financial data contributes HIGH to both confidentiality and integrity, while Client name contributes HIGH to availability. Therefore the correct aggregate is HIGH, HIGH, HIGH, not an average or median of the values.

DMEDIUM, MEDIUM, MEDIUM

MEDIUM, MEDIUM, MEDIUM is the existing incorrect aggregate that fails to apply the high water mark principle and underrepresents the true sensitivity of the combined dataset.

Concept tested: Data classification high water mark aggregation

Source: https://csrc.nist.gov/publications/detail/sp/800-60/vol-1/final

Topics

#data classification#CIA triad aggregation#risk scoring#information assurance

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice