nerdexam
CompTIA

CAS-003 · Question #447

A legacy web application, which is being used by a hospital, cannot be upgraded for 12 months. A new vulnerability is found in the legacy application, and the networking team is tasked with…

The correct answer is A. ALE D. ARO. ROI for a security control is calculated by comparing the cost of the control against the Annual Loss Expectancy (ALE). ALE is derived from multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO), making both values required inputs.

Risk Management

Question

A legacy web application, which is being used by a hospital, cannot be upgraded for 12 months. A new vulnerability is found in the legacy application, and the networking team is tasked with mitigation. Middleware for mitigation will cost $100,000 per year. Which of the following must be calculated to determine ROI? (Choose two.)

Options

  • AALE
  • BRTO
  • CMTBF
  • DARO
  • ERPO

How the community answered

(37 responses)
  • A
    78% (29)
  • B
    14% (5)
  • C
    3% (1)
  • E
    5% (2)

Why each option

ROI for a security control is calculated by comparing the cost of the control against the Annual Loss Expectancy (ALE). ALE is derived from multiplying the Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO), making both values required inputs.

AALECorrect

ALE (Annual Loss Expectancy) represents the expected yearly financial loss from a risk, calculated as SLE x ARO. Comparing the $100,000 annual middleware cost against the ALE determines whether the investment is justified and yields a positive ROI.

BRTO

RTO (Recovery Time Objective) defines the maximum tolerable downtime for a system; it is a business continuity metric, not a financial risk calculation input.

CMTBF

MTBF (Mean Time Between Failures) measures hardware reliability and availability; it informs maintenance decisions but is not a direct input to the ALE-based ROI formula.

DAROCorrect

ARO (Annualized Rate of Occurrence) quantifies how often a threat is expected to occur per year. Without ARO, ALE cannot be calculated, making it a required component of the ROI determination.

ERPO

RPO (Recovery Point Objective) defines the acceptable amount of data loss measured in time; it is a business continuity metric unrelated to the financial ROI calculation for a security control.

Concept tested: Calculating security control ROI using ALE and ARO

Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final

Topics

#ALE#ARO#risk quantification#ROI calculation

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice