nerdexam
ExamsCAS-003Questions#488
CompTIA

CAS-003 · Question #488

CAS-003 Question #488: Real Exam Question with Answer & Explanation

The correct answer is D: Number of accounts accessing the system per day. A Key Risk Indicator must measure the risk most relevant to the asset's value and threat profile. The system holds non-public intellectual property in archived contracts that are no longer actively used-meaning legitimate access should be rare and limited to a small, known set of

Question

A Chief Information Security Officer (CISO) needs to establish a KRI for a particular system. The system holds archives of contracts that are no longer in use. The contracts contain intellectual property and have a data classification of non-public. Which of the following be the BEST risk indicator for this system?

Options

  • AAverage minutes of downtime per quarter
  • BPercent of patches applied in the past 30 days
  • CCount of login failures per week
  • DNumber of accounts accessing the system per day

Explanation

A Key Risk Indicator must measure the risk most relevant to the asset's value and threat profile. The system holds non-public intellectual property in archived contracts that are no longer actively used-meaning legitimate access should be rare and limited to a small, known set of users. The primary risk is unauthorized access leading to data theft or leakage. Tracking the number of accounts accessing the system per day (D) directly measures this risk: any unexpected spike or access by unrecognized accounts signals a potential breach. Average downtime (A) is irrelevant because the contracts are inactive and high availability is not a business requirement. Patch compliance (B) is a general hygiene metric, not specific to the data-theft risk of this archive. Login failures per week (C) captures failed attempts but misses the more dangerous scenario of successful unauthorized access, which this KRI must detect.

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice