nerdexam
CompTIA

CAS-003 · Question #872

While reviewing wire transfer procedures, the Chief Information Security Officer (CISO) of a bank discovers a flaw in the policy that can potentially allow for some wire transfers to occur without…

The correct answer is B. Mitigated risk. After a compensating control is applied to a known policy flaw, the risk that has been partially addressed but not fully eliminated is classified as mitigated risk.

Risk Management

Question

While reviewing wire transfer procedures, the Chief Information Security Officer (CISO) of a bank discovers a flaw in the policy that can potentially allow for some wire transfers to occur without the account owner’s consent. The CISO recommends a compensating control, which is implemented immediately by operational staff, although there is still some risk posed to the bank. Which of the following BEST describes the CISO’s new concerns about wire transfer fraud?

Options

  • AResidual risk
  • BMitigated risk
  • CInherent risk
  • DAccepted risk

How the community answered

(53 responses)
  • A
    4% (2)
  • B
    87% (46)
  • C
    8% (4)
  • D
    2% (1)

Why each option

After a compensating control is applied to a known policy flaw, the risk that has been partially addressed but not fully eliminated is classified as mitigated risk.

AResidual risk

Residual risk is the risk remaining after all planned controls including primary controls are fully in place, whereas here the focus is on the act of reducing risk via a compensating control rather than what persists after a full control framework is applied.

BMitigated riskCorrect

Mitigated risk describes risk that has been reduced through the deliberate application of a control or countermeasure - in this case the compensating control deployed by operational staff to close the policy gap. The CISO's continued concern stems from the fact that the mitigation reduced but did not fully eliminate the exposure, which is the defining characteristic of a mitigated risk state.

CInherent risk

Inherent risk is the level of risk that exists before any controls are applied at all, which does not apply here because a compensating control has already been implemented.

DAccepted risk

Accepted risk means an organization has acknowledged a risk and chosen not to mitigate it further, which contradicts the scenario where the CISO actively recommended and deployed a compensating control.

Concept tested: Risk classification - mitigated vs inherent vs residual vs accepted

Source: https://csrc.nist.gov/glossary/term/risk_mitigation

Topics

#residual risk#compensating controls#risk terminology#risk treatment

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice