nerdexam
CompTIA

CAS-003 · Question #694

As part of a systems modernization program, the use of a weak encryption algorithm is identified m a wet se-vices API. The client using the API is unable to upgrade the system on its end which would…

The correct answer is C. Mitigation. The ACL is an example of risk Mitigation. Mitigation means taking action to reduce the likelihood or impact of a risk without fully eliminating it. The weak encryption vulnerability still exists, but restricting API access to only the client's known IP space reduces the attack…

Risk Management

Question

As part of a systems modernization program, the use of a weak encryption algorithm is identified m a wet se-vices API. The client using the API is unable to upgrade the system on its end which would support the use of a secure algorithm set. As a temporary workaround the client provides its IP space and the network administrator Limits access to the API via an ACL to only the IP space held by the client. Which of the following is the use of the ACL in this situation an example of?

Options

  • AAvoidance
  • BTransference
  • CMitigation
  • DAcceptance
  • EAssessment

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    93% (28)

Explanation

The ACL is an example of risk Mitigation. Mitigation means taking action to reduce the likelihood or impact of a risk without fully eliminating it. The weak encryption vulnerability still exists, but restricting API access to only the client's known IP space reduces the attack surface - fewer actors can reach the vulnerable endpoint. Avoidance (A) would mean shutting down the API entirely; Transference (B) would mean shifting the risk to a third party (e.g., insurance); Acceptance (D) would mean acknowledging the risk and doing nothing; Assessment (E) is a process, not a treatment strategy.

Topics

#risk treatment#compensating controls#ACL#weak encryption

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice