H19-401_V1.0 · Question #121
There are () levels of application/application service sensitivity
The correct answer is A. 3. Option A (3) is correct because most information security and IT governance frameworks - including NIST FIPS 199 and common enterprise classification models - define exactly three levels of application/application service sensitivity: Low, Moderate (Medium), and High, based on…
Question
There are () levels of application/application service sensitivity
Options
- A3
- B4
- C2
How the community answered
(17 responses)- A82% (14)
- B6% (1)
- C12% (2)
Explanation
Option A (3) is correct because most information security and IT governance frameworks - including NIST FIPS 199 and common enterprise classification models - define exactly three levels of application/application service sensitivity: Low, Moderate (Medium), and High, based on the potential impact of a security breach on confidentiality, integrity, or availability.
Option B (4) is incorrect; adding a fourth level (such as "Critical" or "Very High") is not standard in the widely adopted frameworks this question is based on, even though some proprietary models occasionally extend to four tiers.
Option C (2) is incorrect; a two-level binary split (e.g., "sensitive / non-sensitive") is too coarse to capture the meaningful distinctions between moderate-impact and high-impact systems, which require different security controls.
Memory tip: Think of the traffic light analogy - Green (Low), Yellow (Moderate), Red (High) - three colors, three sensitivity levels. If you can picture a stoplight, you'll always remember there are 3.
Topics
Community Discussion
No community discussion yet for this question.