CAS-003 · Question #755
A company's Chief Information Security Officer (CISO) is working with the product owners to perform a business impact assessment. The product owners provide feedback related to the critically of…
The correct answer is A. Trend analysis C. TCO. The stated answer of A (Trend Analysis) and C (TCO) appears to be incorrect. Risk ranking in a risk assessment is determined by two fundamental components: Likelihood (B) - the probability that a threat event will occur - and Magnitude (E) - the severity of impact if it does…
Question
A company's Chief Information Security Officer (CISO) is working with the product owners to perform a business impact assessment. The product owners provide feedback related to the critically of various business processes, personal, and technologies. Transitioning into risk assessment activities, which of the following types of information should the CISO require to determine the proper risk ranking? (Select TWO).
Options
- ATrend analysis
- BLikelihood
- CTCO
- DCompensating controls
- EMagnitude
- FROI
How the community answered
(69 responses)- A75% (52)
- B1% (1)
- D12% (8)
- E4% (3)
- F7% (5)
Explanation
The stated answer of A (Trend Analysis) and C (TCO) appears to be incorrect. Risk ranking in a risk assessment is determined by two fundamental components: Likelihood (B) - the probability that a threat event will occur - and Magnitude (E) - the severity of impact if it does occur. Risk = Likelihood × Magnitude. Trend analysis informs threat intelligence but is not a risk ranking input, and TCO (Total Cost of Ownership) is a financial evaluation metric unrelated to ranking risk. Compensating controls (D) are mitigations, ROI (F) is a financial metric, and neither determines risk rank.
Topics
Community Discussion
No community discussion yet for this question.