nerdexam
CompTIA

CAS-002 · Question #872

ODBC access to a database on a network-connected host is required. The host does not have a security mechanism to authenticate the incoming ODBC connection, and the application requires that the…

The correct answer is B. Explain the risks to the data owner and aid in the decision to accept the risk versus choosing a. When a system presents risk due to unauthenticated ODBC access, the security analyst must explain the risks to the data owner and support an informed risk acceptance decision.

Integration of Computing, Communications and Business Disciplines

Question

ODBC access to a database on a network-connected host is required. The host does not have a security mechanism to authenticate the incoming ODBC connection, and the application requires that the connection have read/write permissions. In order to further secure the data, a nonstandard configuration would need to be implemented. The information in the database is not sensitive, but was not readily accessible prior to the implementation of the ODBC connection. Which of the following actions should be taken by the security analyst?

Options

  • AAccept the risk in order to keep the system within the company's standard security configuration.
  • BExplain the risks to the data owner and aid in the decision to accept the risk versus choosing a
  • CSecure the data despite the need to use a security control or solution that is not within company
  • DDo not allow the connection to be made to avoid unnecessary risk and avoid deviating from the

How the community answered

(31 responses)
  • A
    10% (3)
  • B
    68% (21)
  • C
    3% (1)
  • D
    19% (6)

Why each option

When a system presents risk due to unauthenticated ODBC access, the security analyst must explain the risks to the data owner and support an informed risk acceptance decision.

AAccept the risk in order to keep the system within the company's standard security configuration.

Accepting risk without involving the data owner bypasses proper governance and removes the responsible party's ability to make an informed decision about risks to their own data.

BExplain the risks to the data owner and aid in the decision to accept the risk versus choosing aCorrect

The data owner holds authority and accountability for decisions regarding their data, so the security analyst's role is to explain the technical risks clearly and help the data owner make an informed decision between accepting the risk or implementing a nonstandard control - this follows proper risk governance and avoids unilateral decisions that ignore business context.

CSecure the data despite the need to use a security control or solution that is not within company

Implementing nonstandard security controls without data owner involvement and proper change management exceeds the security analyst's authority and skips required approval processes.

DDo not allow the connection to be made to avoid unnecessary risk and avoid deviating from the

Blocking the connection without consulting the data owner is a unilateral decision that ignores legitimate business requirements and does not follow proper risk management procedures.

Concept tested: Risk acceptance and data owner responsibility

Source: https://csrc.nist.gov/publications/detail/sp/800-37/rev-2/final

Topics

#risk acceptance#ODBC security#data ownership#risk communication

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice