exam questions

Exam CAS-005 All Questions

View all questions & answers for the CAS-005 exam

Exam CAS-005 topic 1 question 51 discussion

Actual exam question from CompTIA's CAS-005
Question #: 51
Topic #: 1
[All CAS-005 Questions]

Which of the following describes how a risk assessment is performed when an organization has a critical vendor that provides multiple products?

  • A. At the individual product level
  • B. Through the selection of a random product
  • C. Using a third-party audit report
  • D. By choosing a major product
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
vicbersong
1 week, 1 day ago
Selected Answer: A
✅ A. At the individual product level 🔍 Explanation: When a critical vendor supplies multiple products, a proper risk assessment should be conducted for each product individually. This is because: Each product may have different security risks, data sensitivities, compliance requirements, or integration points with your systems. Assessing risk at the vendor level alone may miss product-specific vulnerabilities or operational dependencies. ❌ Why the other options are incorrect: B. Through the selection of a random product This introduces bias and does not ensure full visibility into the vendor's risk posture. C. Using a third-party audit report Helpful as supplemental evidence, but not a replacement for a tailored risk assessment. D. By choosing a major product May miss risks in less critical but still impactful products.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago