Welcome to ExamTopics
ExamTopics Logo
- Expert Verified, Online, Free.

Unlimited Access

Get Unlimited Contributor Access to the all ExamTopics Exams!
Take advantage of PDF Files for 1000+ Exams along with community discussions and pass IT Certification Exams Easily.

Exam CAS-004 topic 1 question 184 discussion

Actual exam question from CompTIA's CAS-004
Question #: 184
Topic #: 1
[All CAS-004 Questions]

A company just released a new video card. Due to limited supply and high demand, attackers are employing automated systems to purchase the device through the company's web store so they can resell it on the secondary market. The company's intended customers are frustrated. A security engineer suggests implementing a CAPTCHA system on the web store to help reduce the number of video cards purchased through automated systems.
Which of the following now describes the level of risk?

  • A. Inherent
  • B. Low
  • C. Mitigated
  • D. Residual
  • E. Transferred
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?) , you can switch to a simple comment.
Switch to a voting comment New
[Removed]
Highly Voted 1 year, 6 months ago
Selected Answer: D
CAPTCHA does not completely mitigate the risk of Bots but rather reduces the risk and therefore Residual risk remains after the CAPTCHA implementation.
upvoted 7 times
...
ddcnsd65
Most Recent 1 week, 4 days ago
https://www.pwc.com/cyber/digital-trust
upvoted 1 times
...
ddcnsd65
1 week, 4 days ago
D Is Resdidual risk a "level" of risk in cybersecurity? Yes, "resdidual" risk is a level of risk in cybersecurity that refers to the risk that remains after security measures have been implemented. It is the risk that an event will still occur despite the implementation of risk management controls or stratagies. For example, if an organization implements an email security service to detect spamd and phishing attacks, but continues to receive phishing emails, that's an example of "residual" risk.
upvoted 1 times
...
suprman4485
2 months ago
It says "level", the only one listed that is a cybersecurity level and makes sense is Low.
upvoted 1 times
...
userguy890
2 months, 2 weeks ago
Selected Answer: A
The question never says they implemented captcha, only suggested. This is a trick question so its A. However if the question is mistyped then it may be D.
upvoted 1 times
...
ElDirec
3 months ago
Selected Answer: A
Inherent Risk LOL Trick question: ChatGPT doesn't know how to solve trick questions. If you're broke, and I suggest, you get a job in cybersecurity. How are your finances now?
upvoted 1 times
...
talosDevbot
3 months, 3 weeks ago
Selected Answer: D
"Residual risk is the risk that remains after your organization has taken proper precautions and implemented appropriate controls" - Sybex CASP+ textbook
upvoted 1 times
...
hb0011
3 months, 4 weeks ago
I don't like this question because the leftover risk after the mitigating control is known as Residual risk... but residual risk is not a "level" of risk. A level would be low, medium, high, etc. It's a type of risk.
upvoted 1 times
...
The_Lucifer
4 months ago
question just says captcha was suggested not implemented than shouldn't it be A?
upvoted 1 times
...
Anarckii
4 months, 2 weeks ago
Selected Answer: D
I was stuck between C and D for the longest, but then saw this: if there is still a possibility (residual risk) that some automated systems might bypass the CAPTCHA, then there is a level of risk that remains despite the mitigation efforts. the question reads "help reduce the number of video cards purchased through automated systems" which mean the risk still remains. If it read "lower the chances" or "Likelihood" then it would be C
upvoted 2 times
...
nmap_king_22
6 months, 2 weeks ago
Selected Answer: C
thinking C. the risk is getting lowered due to the new implementation of security measures
upvoted 1 times
...
Ariel235788
7 months, 1 week ago
Selected Answer: C
Copy/Paste from ChatGPT: The level of risk, after implementing the CAPTCHA system on the web store to help reduce the number of video cards purchased through automated systems, can be described as: C. Mitigated. The term "mitigated" refers to the reduction or mitigation of risk through the implementation of security controls or countermeasures. In this case, the CAPTCHA system is a security control that aims to reduce the risk of automated systems purchasing video cards by adding a layer of human verification, thus mitigating the risk of unauthorized purchases.
upvoted 1 times
...
BiteSize
9 months, 3 weeks ago
Selected Answer: D
Residual is what is left. Cannot completely mitigate a risk unless you turn off your network. The question is a weird wording as in lets tell a story and you answer like it is a story. yes, current state is Inherent and after controls are implemented it is in a mitigated state. however, this whole what if type of framing makes Residual the answer. Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence) Source: Verifying each answer against Chat GPT, my experience, other test banks, a written book, and weighing in the discussion from all users to create a 100% accurate guide for myself before I take the exam. (It isn't easy because of the time needed, but it is doing my diligence)
upvoted 4 times
...
BreakOff874
1 year ago
Selected Answer: A
The CAPTCHA was suggested but it was never implemented. Inherent risk refers to the risk that exists before any controls or mitigations have been applied. In this case, since the CAPTCHA system has not been implemented yet, the risk associated with attackers employing automated systems to purchase the video cards is still at its inherent level.
upvoted 3 times
...
hidady
1 year, 4 months ago
D is the correct answer
upvoted 3 times
javier051977
1 year, 1 month ago
The level of risk in option E, Transferred, would be appropriate if the company had transferred the responsibility for managing the risk to a third party. For example, if the company had outsourced the management of its web store to a third-party provider that assumed the responsibility for managing the risk of automated purchases, then it would be appropriate to describe the level of risk as transferred.
upvoted 1 times
javier051977
1 year, 1 month ago
However, in this scenario, the company itself is proposing the solution of implementing a CAPTCHA system to mitigate the risk of automated purchases. Therefore, the responsibility for managing the risk remains with the company.
upvoted 1 times
...
...
...
dangerelchulo
1 year, 8 months ago
I was confused a little about why residual but the risk that someone can by pass the bot catcher is possible also, if the buyer decides to buy them by authenticating manually the risk still remain so is not mitigated but you have residual risk now.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...