ExamGecko
Home / CompTIA / CAS-004 / Practice Test 2
Ask Question

CompTIA CAS-004 Practice Test 2

00:00:00
Show Answer
Report Issue   Restart test

Question 1 / 40

A security analyst is performing a vulnerability assessment on behalf of a client. The analyst must define what constitutes a risk to the organization.

Which of the following should be the analyst's FIRST action?

Create a full inventory of information and data assets.
Create a full inventory of information and data assets.
Ascertain the impact of an attack on the availability of crucial resources.
Ascertain the impact of an attack on the availability of crucial resources.
Determine which security compliance standards should be followed.
Determine which security compliance standards should be followed.
Perform a full system penetration test to determine the vulnerabilities.
Perform a full system penetration test to determine the vulnerabilities.
Comment (0)
Suggested answer: A
Explanation:

This is because a risk assessment requires identifying the assets that are valuable to the organization and could be targeted by attackers. A full inventory of information and data assets can help the analyst prioritize the most critical assets and determine their potential exposure to threats. Without knowing what assets are at stake, the analyst cannot effectively assess the risk level or the impact of an attack. Creating an inventory of assets is also a prerequisite for performing other actions, such as following compliance standards, measuring availability, or conducting penetration tests.

asked 02/10/2024
Mohamed Iftiquar Aslam Hameed
41 questions