ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 496 - CAS-004 discussion

Report
Export

A security analyst is participating in a risk assessment and is helping to calculate the exposure factor associated with various systems and processes within the organization. Which of the following resources would be most useful to calculate the exposure factor in this scenario?

A.
Gap analysis
Answers
A.
Gap analysis
B.
Business impact analysis
Answers
B.
Business impact analysis
C.
Risk register
Answers
C.
Risk register
D.
Information security policy
Answers
D.
Information security policy
E.
Lessons learned
Answers
E.
Lessons learned
Suggested answer: B

Explanation:

A business impact analysis (BIA) is the most useful resource for calculating the exposure factor in a risk assessment. The BIA helps identify the criticality of systems and processes and quantifies the potential financial and operational impact of vulnerabilities being exploited. By understanding the business impact, the security team can more accurately determine the exposure factor, which is the proportion of an asset's value that is at risk in the event of a security incident. CASP+ highlights the role of BIAs in understanding risk exposure and supporting effective risk management decisions.

CASP+ CAS-004 Exam Objectives: Domain 1.0 -- Risk Management (Business Impact Analysis and Risk Exposure)

CompTIA CASP+ Study Guide: Business Impact Analysis for Risk Assessment

asked 02/10/2024
Kamil Stonjek
36 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first