QBank Quiz August 26, 2024 Test ID: 307809881

EXAM ELABORATIONS Aug 30, 2025
Loading...

Loading document viewer...

Page 0 of 0

Document Text

QBank Quiz August 26, 2024 Test ID: 307809881

Question #1 of 54 Question ID: 1509063

Which of the following would require an organization to complete the risk management process prior to its deployment?

  • service pack for client operating systems
  • new sales tracking application to be used in-house
  • security patches for an email application already in use
  • firmware updates to deployed routers
  • Explanation An organization should complete the risk management process prior to deploying a new sales tracking application. Every application should be developed according to a secure software development life cycle (SDLC). This includes evaluating the risks and benefits that this application would provide. That is, a determination must be made about the value of the sales data and the risk to the organization if that data is corrupted or stolen. Even though it will be used exclusively in-house, it must go through the secure SDLC process to ensure that database(s) being used to store the sales data are securely protected against unauthorized access, either through vulnerabilities in the code such as buffer overflows or input fields that are not sanitized . The application should be thoroughly tested for vulnerabilities over and above vulnerability scans, including penetration tests to determine additional vulnerabilities, and ensure careful development of any included APIs.While patches, updates, and service packs would need formal testing prior to deployment, they would not require a full risk management process because they are purely updates to existing technologies. The risk management process would have been completed prior to deploying the applications or technologies to which they apply.

Objective:

Governance, Risk, and Compliance 1 / 4

Sub-Obijective:

Given a set of requirements, apply the appropriate risk strategies

References:

CompTIA Advanced Security Practitioner (CASP+) CAS-004 Cert Guide, Chapter 25: Applying Appropriate Risk Strategies

Question #2 of 54 Question ID: 1509043

Your organization has purchased a new security device. You have determined that the MTBF is six months and the MTTR is one day. The cost for each failure is estimated to be $5,000. The vendor has offered your organization a three-year maintenance plan for $10,000. You could also purchase an identical device to act as backup for $20,000. Another option is to hire a security practitioner who will be tasked with maintaining the security devices on the network for an annual salary of $45,000.You must protect your organization against the risk of failure in the most cost-efficient manner as possible.What should you do?

  • Purchase the maintenance plan.
  • Hire the security practitioner.
  • Accept the risk.
  • Purchase the identical device.
  • Explanation You should purchase the maintenance plan. This is the most cost-efficient solution as this would only cost $10,000.You would not purchase an identical device as this would cost $20,000.You would not accept the risk. If the mean time between failures (MTBF) is six months, then failures would occur twice a year. With a cost of $5,000 each, the failures would cost $10,000 a year, which translates into $30,000 over a three-year period, making the maintenance plan a far cheaper option.You would not hire the security practitioner. This would be the most expensive solution. 2 / 4

Objective:

Governance, Risk, and Compliance

Sub-Objective:

Given a set of requirements, apply the appropriate risk strategies

References:

CompTIA Advanced Security Practitioner (CASP+) CAS-004 Cert Guide, Chapter 25: Applying Appropriate Risk Strategies

Question #3 of 54 Question ID: 1509088

Your organization is analyzing the security solutions that were previously deployed to meet business needs. As part of this analysis, you have been asked to determine the amount of delay caused by the deployment of certain security mechanisms. What is the term used to describe the specific information you are researching?

  • capability
  • scalability
  • latency
  • availability
  • usability
  • Explanation You are researching the latency of the security mechanisms. M Avalilability is the up- and downtime of a system or device. Scalability is the ability of a device or application to continue to meet functional requirements when volume or throughput changes. Capability is the ability of an application or device to meet a specific goal. Usability is the degree to which an application or device can be used to achieve specific goals. 3 / 4

Other terms that you should know for the CASP+ exam include:

» Performance — the level at which the security solution provides a service.« Maintainability — the ability of an application or device to be maintained for a specific amount of time. Maintainability should consider both hardware and software updates that will be needed.

  • Recoverability — the ability of the security solution to recover from a failure.
  • All of these terms help security professionals to analyze security-solution metrics and attributes to ensure they meet business needs.Concepts you need to know regarding business continuity and disaster recovery for the CASP+ exam include: « Recovery service level agreement (RSL) — An RSL is an agreement that a disaster recovery company or cloud provider will ensure that an organization's recovery time objective (RTO) and recovery point objective (RPO) are met in the event of a disaster. Various companies offer varying levels of service based on how much downtime to the system is permissible. Metrics that help define a recovery service level include response time, technical systems specifications, recovery facility access, and security guarantees.« Mission-essential functions (MEFs) — These include all the functions or operations that a business needs to keep running throughout or after a brief pause in the event of a disaster or disruption of services. The actual functions are those that are specified in the company’s executive charter.» Privacy impact assessment (PIA) — This is the process of analyzing all the risks and impacts associated with privacy protection for a company when assessing new business ventures or projects. A PlIA is based on the needs of both the company and its customers whose data privacy needs to be protected. A company performing a PIA needs to analyze its processes to determine how the privacy of its customers could be compromised.» Incident response roles and responsibilities — An incident response (IR) plan contains steps for successfully responding to and mitigating a cyber- attack. The plan needs to include all the personnel who will take ownership for an incident and specify their individual roles and responsibilities.Playbooks provide documentation of an organization's IR plan. They describe the exact steps and processes to be followed for specific incidents. It also includes ways to contact the team responsible for each type of incident. The playbook needs to be updated on an ongoing basis. It needs to be made available to each IR team member and used along with existing business continuity and disaster recovery plans.

Concepts related to testing plans for business continuity include:

. -t — This contains resource assignment, documentation testing, checklist testing containing scenarios and use cases, compliance information, and measurability of testing project deliverables.. Mh — This is an informal process where a presenter guides participants through a disaster recovery (DR) scenario for the purposes of gaining feedback and sharing information. A walk-through also helps in discussing the feasibility of any proposed DR suggestions and options.

  • / 4

Download Document

Buy This Document

$30.00 One-time purchase
Buy Now
  • Full access to this document
  • Download anytime
  • No expiration

Document Information

Category: EXAM ELABORATIONS
Added: Aug 30, 2025
Description:

QBank Quiz August 26, 2024 Test ID: 307809881 Question # Question ID: 1509063 Which of the following would require an organization to complete the risk management process prior to its deployment? A...

Get this document $30.00