nerdexam
CompTIA

CAS-003 · Question #341

A newly hired security analyst has joined an established SOC team. Not long after going through corporate orientation, a new attack method on web-based applications was publicly revealed. The…

The correct answer is A. The organization has accepted the risks associated with web-based threats. Risk acceptance is a formal risk management decision in which an organization acknowledges a risk and deliberately chooses not to implement additional controls, typically because the cost of mitigation exceeds the potential impact or compensating controls already exist. If the…

Risk Management

Question

A newly hired security analyst has joined an established SOC team. Not long after going through corporate orientation, a new attack method on web-based applications was publicly revealed. The security analyst immediately brings this new information to the team lead, but the team lead is not concerned about it. Which of the following is the MOST likely reason for the team lead's position?

Options

  • AThe organization has accepted the risks associated with web-based threats.
  • BThe attack type does not meet the organization's threat model.
  • CWeb-based applications are on isolated network segments.
  • DCorporate policy states that NIPS signatures must be updated every hour.

How the community answered

(70 responses)
  • A
    73% (51)
  • B
    4% (3)
  • C
    9% (6)
  • D
    14% (10)

Explanation

Risk acceptance is a formal risk management decision in which an organization acknowledges a risk and deliberately chooses not to implement additional controls, typically because the cost of mitigation exceeds the potential impact or compensating controls already exist. If the team lead is unconcerned about a newly disclosed web-based attack method, the most likely explanation is that the organization has already formally accepted the risk associated with web-based threats. This would be documented in the risk register and communicated to the SOC. The new analyst's unfamiliarity with this accepted risk posture explains the disconnect.

Topics

#risk acceptance#threat modeling#SOC operations#web application security

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice