nerdexam
CompTIA

CAS-003 · Question #464

A security analyst is classifying data based on input from data owners and other stakeholders. The analyst has identified three data types: 1. Financially sensitive data 2. Project data 3. Sensitive…

The correct answer is A. Conduct a quantitative evaluation of the risks associated with commingling the data and reject or. When stakeholders raise concerns about industrial espionage risks from commingling sensitive project data, the analyst's best course of action is to conduct a quantitative risk evaluation. A quantitative approach assigns measurable values (financial impact, probability) to the…

Risk Management

Question

A security analyst is classifying data based on input from data owners and other stakeholders. The analyst has identified three data types: 1. Financially sensitive data 2. Project data 3. Sensitive project data The analyst proposes that the data be protected in two major groups, with further access control separating the financially sensitive data from the sensitive project data. The normal project data will be stored in a separate, less secure location. Some stakeholders are concerned about the recommended approach and insist that commingling data from different sensitive projects would leave them vulnerable to industrial espionage. Which of the following is the BEST course of action for the analyst to recommend?

Options

  • AConduct a quantitative evaluation of the risks associated with commingling the data and reject or
  • BMeet with the affected stakeholders and determine which security controls would be sufficient to
  • CUse qualitative methods to determine aggregate risk scores for each project and use the derived
  • DIncrease the number of available data storage devices to provide enough capacity for physical

How the community answered

(32 responses)
  • A
    63% (20)
  • B
    6% (2)
  • C
    9% (3)
  • D
    22% (7)

Explanation

When stakeholders raise concerns about industrial espionage risks from commingling sensitive project data, the analyst's best course of action is to conduct a quantitative risk evaluation. A quantitative approach assigns measurable values (financial impact, probability) to the specific risks of each data grouping option, providing objective evidence to support or reject the proposed approach. This gives decision-makers concrete data rather than subjective assessments and allows the analyst to formally document whether the commingling risk is acceptable. Simply meeting with stakeholders (B) without a structured evaluation framework does not resolve the underlying dispute. Qualitative aggregate scores (C) are less convincing to stakeholders requiring hard evidence. Adding storage devices (D) addresses capacity, not the access control and espionage concern.

Topics

#data classification#data commingling#access controls#quantitative risk assessment

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice