nerdexam
ExamsCAS-003Questions#270
CompTIA

CAS-003 · Question #270

CAS-003 Question #270: Real Exam Question with Answer & Explanation

Sign in or unlock CAS-003 to reveal the answer and full explanation for question #270. The question stem and answer options stay visible for context.

Question

Following a security assessment, the Chief Information Security Officer (CISO) is reviewing the results of the assessment and evaluating potential risk treatment strategies. As part of the CISO's evaluation, a judgment of potential impact based on the identified risk is performed. To prioritize response actions, the CISO uses past experience to take into account the exposure factor as well as the external accessibility of the weakness identified. Which of the following is the CISO performing?

Options

  • ADocumentation of lessons learned
  • BQuantitative risk assessment
  • CQualitative assessment of risk
  • DBusiness impact scoring
  • EThreat modeling

Unlock CAS-003 to see the answer

You've previewed enough free CAS-003 questions. Unlock CAS-003 for full answers, explanations, the timed quiz mode, progress tracking, and the master PDF. Question stem and options stay visible so you can still see what's on the exam.

Full CAS-003 Practice