nerdexam
CompTIA

CAS-003 · Question #903

The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the networks. However the…

The correct answer is B. The threat model was not vetted property. If a security plan is 'robust' yet attacks still succeed, the most likely root cause is a flawed threat model - the foundational assumption about who the adversaries are, how they operate, and which attack vectors they exploit. A threat model that was not properly vetted may…

Risk Management

Question

The Chief Information Security Officer (CISO) developed a robust plan to address both internal and external vulnerabilities due to an increase in ransomware attacks on the networks. However the number of successful attacks continues to increase. Which of the following is the MOST likely failure?

Options

  • AThe company did not blacklist suspected websites properly
  • BThe threat model was not vetted property
  • CThe IDS/IPS were not updated with the latest malware signatures
  • DThe organization did not conduct a business impact analysis

How the community answered

(29 responses)
  • A
    34% (10)
  • B
    45% (13)
  • C
    14% (4)
  • D
    7% (2)

Explanation

If a security plan is 'robust' yet attacks still succeed, the most likely root cause is a flawed threat model - the foundational assumption about who the adversaries are, how they operate, and which attack vectors they exploit. A threat model that was not properly vetted may have missed key ransomware delivery vectors such as phishing, RDP exploitation, or supply chain compromise, causing the resulting controls to address the wrong attack surface. Option A (website blacklisting) is a reactive, low-efficacy control against modern ransomware and its absence is a symptom, not a root cause. Option C (IDS/IPS signatures) is an operational gap, not a strategic planning failure. Option D (BIA) relates to recovery planning rather than attack prevention. The threat model is the upstream artifact that shapes the entire plan - errors there cascade into all downstream controls.

Topics

#threat modeling#ransomware#security control failure#risk assessment

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice