nerdexam
CompTIA

CAS-003 · Question #503

Company leadership believes employees are experiencing an increased number of cyber attacks; however, the metrics do not show this. Currently, the company uses "Number of successful phishing…

The correct answer is C. The number of unsuccessful phishing attacks. The “Number of successful phishing attacks” alone does not mean a lot, since you must know how many phishing attacks are done. This way, IMHO “C. The number of unsuccessful phishing attacks” and “D. The percent of successful phishing attacks” would be correct. I would mark C…

Risk Management

Question

Company leadership believes employees are experiencing an increased number of cyber attacks; however, the metrics do not show this. Currently, the company uses "Number of successful phishing attacks" as a KRI, but it does not show an increase. Which of the following additional information should be the Chief Information Security Officer (CISO) include in the report?

Options

  • AThe ratio of phishing emails to non-phishing emails
  • BThe number of phishing attacks per employee
  • CThe number of unsuccessful phishing attacks
  • DThe percent of successful phishing attacks

How the community answered

(34 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    85% (29)
  • D
    9% (3)

Explanation

The “Number of successful phishing attacks” alone does not mean a lot, since you must know how many phishing attacks are done. This way, IMHO “C. The number of unsuccessful phishing attacks” and “D. The percent of successful phishing attacks” would be correct. I would mark C, since it complements the KRI you already have.

Topics

#KRI#phishing metrics#security reporting#risk indicators

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice