CAS-003 · Question #809
A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts: Which of the following MOST appropriate…
The correct answer is A. The product owner should perform a business impact assessment regarding the ability to. Although the vulnerability scan output is not shown in full, the corrective action documented directs the product owner to perform a Business Impact Assessment (BIA). This is appropriate when a finding involves a product or component that is end-of-life, unsupported, or cannot…
Question
A Chief information Security Officer (CISO) is developing corrective-action plans based on the following from a vulnerability scan of internal hosts:
Which of the following MOST appropriate corrective action to document for this finding?
Exhibit
Options
- AThe product owner should perform a business impact assessment regarding the ability to
- BThe application developer should use a static code analysis tool to ensure any application
- CThe system administrator should evaluate dependencies and perform upgrade as necessary.
- DThe security operations center should develop a custom IDS rule to prevent attacks buffer
How the community answered
(34 responses)- A79% (27)
- B6% (2)
- C3% (1)
- D12% (4)
Explanation
Although the vulnerability scan output is not shown in full, the corrective action documented directs the product owner to perform a Business Impact Assessment (BIA). This is appropriate when a finding involves a product or component that is end-of-life, unsupported, or cannot be immediately patched - situations where a technical fix may not be straightforward. A BIA evaluates the operational and financial impact of the vulnerability on the business, helping leadership make informed decisions about whether to accept the risk, replace the product, or isolate it. This is a management/governance-level corrective action, which is appropriate when the CISO is the one developing the plan.
Topics
Community Discussion
No community discussion yet for this question.
