nerdexam
CompTIA

CAS-003 · Question #755

A company's Chief Information Security Officer (CISO) is working with the product owners to perform a business impact assessment. The product owners provide feedback related to the critically of…

The correct answer is A. Trend analysis C. TCO. The stated answer of A (Trend Analysis) and C (TCO) appears to be incorrect. Risk ranking in a risk assessment is determined by two fundamental components: Likelihood (B) - the probability that a threat event will occur - and Magnitude (E) - the severity of impact if it does…

Risk Management

Question

A company's Chief Information Security Officer (CISO) is working with the product owners to perform a business impact assessment. The product owners provide feedback related to the critically of various business processes, personal, and technologies. Transitioning into risk assessment activities, which of the following types of information should the CISO require to determine the proper risk ranking? (Select TWO).

Options

  • ATrend analysis
  • BLikelihood
  • CTCO
  • DCompensating controls
  • EMagnitude
  • FROI

How the community answered

(69 responses)
  • A
    75% (52)
  • B
    1% (1)
  • D
    12% (8)
  • E
    4% (3)
  • F
    7% (5)

Explanation

The stated answer of A (Trend Analysis) and C (TCO) appears to be incorrect. Risk ranking in a risk assessment is determined by two fundamental components: Likelihood (B) - the probability that a threat event will occur - and Magnitude (E) - the severity of impact if it does occur. Risk = Likelihood × Magnitude. Trend analysis informs threat intelligence but is not a risk ranking input, and TCO (Total Cost of Ownership) is a financial evaluation metric unrelated to ranking risk. Compensating controls (D) are mitigations, ROI (F) is a financial metric, and neither determines risk rank.

Topics

#business impact assessment#risk ranking#risk assessment#likelihood vs magnitude

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice