exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 391 discussion

Actual exam question from CompTIA's CAS-004
Question #: 391
Topic #: 1
[All CAS-004 Questions]

The Chief Information Security Officer (CISO) has outlined a five-year plan for the company that includes the following:

• Implement an application security program.
• Reduce the click rate on phishing simulations from 73% to 8%.
• Deploy EDR to all workstations and servers.
• Ensure all systems are sending logs to the SIEM.
• Reduce the percentage of systems with vulnerabilities from 89% to 5%.

Which of the following would BEST aid the CISO in determining whether these goals are obtainable?

  • A. An asset inventory
  • B. A third-party audit
  • C. A risk assessment
  • D. An organizational CMMI
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
biggytech
Highly Voted 1 year, 5 months ago
Answer is C. Risk Assessment, CMMI is too broad imo whereas Risk assessment will dive deeper into the specific measures
upvoted 7 times
...
Bright07
Most Recent 4 months, 3 weeks ago
Selected Answer: C
A risk assessment involves evaluating the current state of security, identifying potential threats, and assessing the likelihood and impact of those threats. It helps the CISO: Evaluate the current security posture – This includes understanding where the organization stands in terms of application security, phishing awareness, vulnerability management, and other key areas. Prioritize objectives – A risk assessment can help identify the most critical vulnerabilities and areas of concern, allowing the CISO to align the goals with the current risk landscape. Set realistic targets – By assessing the risks, the CISO can better determine whether the goal percentages (e.g., reducing phishing click rate from 73% to 8%) are achievable, based on the organization’s current risk and resource levels. AND Measure success and progress – A comprehensive risk assessment can be used to track progress over time and help adjust strategies accordingly.
upvoted 2 times
...
EAlonso
9 months, 3 weeks ago
Selected Answer: A
The KRI are identified, in a 5-year period many changes can occur in the assets and their exposition to the risk.
upvoted 1 times
...
041ba31
11 months, 2 weeks ago
Selected Answer: C
The best answer is C. A risk assessment. A risk assessment will help the CISO determine the current state of the organization's security posture, identify gaps, and evaluate the feasibility of achieving the outlined goals within the five-year plan.
upvoted 4 times
armid
10 months ago
So he knows very specifically (73, 89 - those dont look to me like rough estimations) how many %'s of assets have vulnerabilities (hence he knows what assets he has and which ones are vulnerable) meaning he already have A and he already did C (or B). Leaving out D. On top of that this is exactly what CMMI is for xD
upvoted 1 times
...
...
e020fdc
1 year, 2 months ago
Selected Answer: D
https://support.isaca.org/s/article/What-is-the-CMMI-Cybermaturity-Platform-1598331743391
upvoted 1 times
...
ElDirec
1 year, 3 months ago
Selected Answer: C
C. A risk assessment would BEST aid the CISO in determining whether these goals are obtainable. A risk assessment involves identifying, evaluating, and prioritizing risks. This process can help the CISO understand the current security posture of the organization, identify gaps or areas of concern, and determine the feasibility of the outlined goals. It can provide valuable insights into whether the goals are realistic given the organization’s current situation and resources. While the other options (An asset inventory, A third-party audit, An organizational CMMI) can provide useful information and contribute to the overall security strategy, they do not directly address the question of whether the specific goals outlined by the CISO are obtainable
upvoted 4 times
...
OdinAtlasSteel
1 year, 5 months ago
Selected Answer: C
Implementing an Organizational Capability Maturity Model Integration (CMMI) could indeed aid the CISO in understanding the organization's process maturity and efficiency. However, when considering the specific goals outlined by the CISO for the five-year plan, a risk assessment (option C) would likely be the more directly relevant and effective approach to determine the feasibility of achieving those goals. The Capability Maturity Model Integration (CMMI) generally focuses on assessing and improving an organization's processes and practices. While it can provide valuable insights into process maturity and efficiency, it may not directly address the specific security objectives outlined in the plan, such as reducing phishing click rates, deploying EDR, ensuring log collection for SIEM, or reducing system vulnerabilities.
upvoted 3 times
ElDirec
1 year, 3 months ago
I want to believe this, but I googled "COMPTIA CMMI" and could not find anything that hints this is what COMPTIA expects
upvoted 1 times
...
...
wizwiz
1 year, 5 months ago
Selected Answer: D
Option D. An organizational Capability Maturity Model Integration (CMMI) would best aid the CISO in determining whether these goals are obtainable. The CMMI is a process and behavioral model that helps organizations streamline process improvement and encourage behaviors that lead to improved performance. By assessing the maturity of the organization’s processes and practices, the CMMI can help determine the feasibility of the CISO’s goals. It can identify strengths and weaknesses in the current approach, and suggest areas for improvement that would increase the likelihood of achieving the outlined goals. While the other options (asset inventory, third-party audit, risk assessment) can provide valuable information and may be part of the overall strategy, they do not provide the comprehensive view of organizational capabilities offered by the CMMI.
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago