nerdexam
CompTIA

CAS-003 · Question #356

Click on the exhibit buttons to view the four messages. A security architect is working with a project team to deliver an important service that stores and processes customer banking details. The…

The correct answer is D. Message 4. An escalation to senior leadership about a missing security control must frame the issue in terms of business risk - regulatory penalties, financial exposure, and reputational harm - rather than technical details.

Risk Management

Question

Click on the exhibit buttons to view the four messages. A security architect is working with a project team to deliver an important service that stores and processes customer banking details. The project, internally known as ProjectX, is due to launch its first set of features publicly within a week, but the team has not been able to implement encryption-at-rest of the customer records. The security architect is drafting an escalation email to senior leadership. Which of the following BEST conveys the business impact for senior leadership?

Exhibits

CAS-003 question #356 exhibit 1
CAS-003 question #356 exhibit 2
CAS-003 question #356 exhibit 3
CAS-003 question #356 exhibit 4

Options

  • AMessage 1
  • BMessage 2
  • CMessage 3
  • DMessage 4

How the community answered

(24 responses)
  • A
    21% (5)
  • B
    13% (3)
  • C
    4% (1)
  • D
    63% (15)

Why each option

An escalation to senior leadership about a missing security control must frame the issue in terms of business risk - regulatory penalties, financial exposure, and reputational harm - rather than technical details.

AMessage 1

Message 1 likely focuses on technical implementation details that are not relevant to the business decision senior leadership must make.

BMessage 2

Message 2 likely understates the risk or frames it in technical terms that do not convey urgency or business consequence to a non-technical audience.

CMessage 3

Message 3 likely presents the issue incompletely or without the explicit connection to regulatory and financial exposure that motivates executive action.

DMessage 4Correct

Message 4 best conveys business impact because senior leadership evaluates risk in terms of organizational consequences such as regulatory fines (e.g., PCI-DSS penalties for unprotected cardholder data), potential breach liability, and reputational damage to customer trust. Framing the absence of encryption-at-rest for banking data in these terms enables executives to make an informed risk acceptance or remediation decision, which is the purpose of the escalation.

Concept tested: Communicating security risk in business impact terms to leadership

Source: https://www.nist.gov/cyberframework

Topics

#risk communication#encryption at rest#business impact#executive reporting

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice