CAS-002 · Question #898
A well-known retailer has experienced a massive credit card breach. The retailer had gone through an audit and had been presented with a potential problem on their network. Vendors were…
The correct answer is C. Quantitative Risk Analysis. Quantitative risk analysis assigns specific monetary values to risk scenarios, making it the correct tool for demonstrating the financial impact of the identified network vulnerability to the retailer.
Question
A well-known retailer has experienced a massive credit card breach. The retailer had gone through an audit and had been presented with a potential problem on their network. Vendors were authenticating directly to the retailer's AD servers, and an improper firewall rule allowed pivoting from the AD server to the DMZ where credit card servers were kept. The firewall rule was needed for an internal application that was developed, which presents risk. The retailer determined that because the vendors were required to have site to site VPN's no other security action was taken. To prove to the retailer the monetary value of this risk, which of the following type of calculations is needed?
Options
- AResidual Risk calculation
- BA cost/benefit analysis
- CQuantitative Risk Analysis
- DQualitative Risk Analysis
How the community answered
(21 responses)- A24% (5)
- B14% (3)
- C57% (12)
- D5% (1)
Why each option
Quantitative risk analysis assigns specific monetary values to risk scenarios, making it the correct tool for demonstrating the financial impact of the identified network vulnerability to the retailer.
Residual risk calculation measures the risk that remains after existing controls are applied, not the monetary value of the specific unmitigated vulnerability that was identified.
A cost/benefit analysis compares the expense of implementing a control against its projected benefit but does not independently quantify the monetary value of the threat itself.
Quantitative Risk Analysis uses metrics such as Single Loss Expectancy (SLE), Annual Rate of Occurrence (ARO), and Annual Loss Expectancy (ALE) to express risk in concrete dollar amounts. This directly satisfies the requirement to prove the monetary value of the AD-to-DMZ pivoting vulnerability, giving decision-makers a financial figure to compare against the cost of remediation. Unlike qualitative methods, quantitative analysis produces specific numerical outputs that support business-case justifications for remediation spending.
Qualitative risk analysis assigns descriptive ratings such as high, medium, or low to risks rather than the specific monetary values needed to prove financial impact.
Concept tested: Quantitative risk analysis - ALE-based monetary valuation
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.