CAS-005 · Question #395
A Chief Information Security Officer requests an action plan to remediate vulnerabilities. A security analyst reviews the output from a recent vulnerability scan and notices hundreds of unique…
The correct answer is B. Business impact analysis. A Business Impact Analysis (BIA) identifies the criticality of systems and the potential impact of their compromise. It helps prioritize which vulnerabilities to remediate first based on the business value and operational impact of the affected assets.
Question
A Chief Information Security Officer requests an action plan to remediate vulnerabilities. A security analyst reviews the output from a recent vulnerability scan and notices hundreds of unique vulnerabilities. The output includes the CVSS score, IP address, hostname, and the list of vulnerabilities. The analyst determines more information is needed in order to decide which vulnerabilities should be fixed immediately. Which of the following is the best source for this information?
Options
- AThird-party risk review
- BBusiness impact analysis
- CIncident response playbook
- DCrisis management plan
How the community answered
(20 responses)- A10% (2)
- B55% (11)
- C25% (5)
- D10% (2)
Explanation
A Business Impact Analysis (BIA) identifies the criticality of systems and the potential impact of their compromise. It helps prioritize which vulnerabilities to remediate first based on the business value and operational impact of the affected assets.
Community Discussion
No community discussion yet for this question.