nerdexam
CompTIA

CAS-003 · Question #871

The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the network. However, the…

The correct answer is B. The threat model was not vetted properly. When a well-designed security plan still fails to stop attacks, the most likely root cause is a flawed threat model that did not accurately represent the actual threat landscape.

Risk Management

Question

The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the network. However, the number of successful attacks continues to increase. Which of the following is the MOST likely failure?

Options

  • AThe company did not blacklist suspected websites properly.
  • BThe threat model was not vetted properly.
  • CThe IDS/IPS were not updated with the latest malware signatures.
  • DThe organization did not conduct a business impact analysis.

How the community answered

(39 responses)
  • A
    5% (2)
  • B
    69% (27)
  • C
    18% (7)
  • D
    8% (3)

Why each option

When a well-designed security plan still fails to stop attacks, the most likely root cause is a flawed threat model that did not accurately represent the actual threat landscape.

AThe company did not blacklist suspected websites properly.

Blacklisting suspected websites addresses only one potential delivery channel for ransomware and is a symptom of a broader control gap rather than the root cause of a comprehensive plan's failure.

BThe threat model was not vetted properly.Correct

A threat model defines which adversaries, attack vectors, and scenarios are in scope for a security program. If the threat model was not properly vetted, it may have excluded the specific ransomware delivery methods or threat actors actually targeting the organization, causing the controls derived from it to be misaligned with real-world attacks. No matter how robustly a plan is implemented, it will fail if the underlying threat assumptions are inaccurate.

CThe IDS/IPS were not updated with the latest malware signatures.

Outdated IDS/IPS signatures are a contributing operational factor but represent a downstream control failure, not the foundational planning failure that would explain a pattern of increasing successful attacks.

DThe organization did not conduct a business impact analysis.

A business impact analysis identifies critical assets and recovery priorities for continuity planning but does not directly inform the design of preventive security controls against ransomware.

Concept tested: Threat modeling accuracy and security plan effectiveness

Source: https://csrc.nist.gov/pubs/sp/800/154/final

Topics

#threat modeling#ransomware#security program failure#root cause analysis

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice