exam questions

Exam CS0-002 All Questions

View all questions & answers for the CS0-002 exam

Exam CS0-002 topic 1 question 176 discussion

Actual exam question from CompTIA's CS0-002
Question #: 176
Topic #: 1
[All CS0-002 Questions]

A security analyst is deploying a new application in the environment. The application needs to be integrated with several existing applications that contain SPI.
Prior to the deployment, the analyst should conduct:

  • A. a tabletop exercise.
  • B. a business impact analysis.
  • C. a PCI assessment.
  • D. an application stress test
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Merc16
Highly Voted 2 years, 8 months ago
Selected Answer: B
Before implementation, BIA needs to be conducted and particularly when dealing with Sensitive Personal information (SPI). Application stress testing can be conducted once you implement the application in a staging environment. Business impact analysis (BIA) is the process of assessing what losses might occur for each threat scenario. For instance, if a roadway bridge crossing a local river is washed out by a flood and employees are unable to reach a business facility for five days, estimated costs to the organization need to be assessed for lost manpower and production. Impacts can be categorized in several ways, such as impacts on life and SAFETY, impacts on finance and REPUTATION, and impacts on PRIVACY.
upvoted 9 times
franbarpro
2 years, 7 months ago
BIA Is not DONE by analysts. It's done by those "C" Guys / Girls.
upvoted 3 times
6yrd7fcv97
2 years, 2 months ago
Not the case - I do BIAs and I don't sit in the C Suite...
upvoted 1 times
...
...
...
RobV
Most Recent 1 year, 6 months ago
Selected Answer: B
B. a business impact analysis. A business impact analysis (BIA) is a crucial step in the risk management process. It helps in identifying and evaluating the potential impacts of disruptions to business operations, including the integration of new applications. In this context, the BIA would assess the impact of the new application on the confidentiality, integrity, and availability of SPI in the existing applications. This analysis helps prioritize security measures and ensure that the integration is done in a way that minimizes risks to the organization. While other assessments such as tabletop exercises, PCI assessments, and application stress tests may also be important in the overall security strategy, they do not directly address the impact on business operations, which is the primary focus of a business impact analysis in this scenario.
upvoted 1 times
...
skibby16
1 year, 7 months ago
Selected Answer: C
A PCI assessment should be conducted prior to the deployment of a new application that contains SPI (Sensitive Personal Information). A PCI assessment is an evaluation of how well an organization complies with the Payment Card Industry Data Security Standard (PCI DSS), which is a set of requirements for protecting cardholder data. PCI DSS applies to any organization that stores, processes, or transmits cardholder data, such as credit card numbers, expiration dates, or security codes4. A PCI assessment can help identify and remediate any gaps or weaknesses in the security controls of an application that handles cardholder data.
upvoted 1 times
...
d8viey
1 year, 7 months ago
Selected Answer: B
Generally, introduction of any new application/service/system into an environment should undergo a BIA. Though these may not be performed by the Analyst, often times they are the ones who informs the system owner one needs to be completed.
upvoted 1 times
...
kumax
1 year, 9 months ago
Keyboard is "SPI / Sensitive Personal Information". ChatGBT: Before deploying a new application that needs to be integrated with several existing applications containing Sensitive Personal Information (SPI), a security analyst should conduct a Privacy Impact Assessment (PIA).
upvoted 1 times
...
uday1985
1 year, 9 months ago
Why you want to do stress testing? was that mentioned even in your dreams?
upvoted 1 times
...
kyky
2 years ago
Selected Answer: B
B. a business impact analysis Before deploying a new application that needs to be integrate with existing applications containing SPI (Sensitive Personally Identifiable) information, a security analyst should conduct a business impact analysis. This analysis helps assess the potential impact on the organization's operations, systems, and data in case of any security incidents or disruptions caused by the new application deployment.
upvoted 1 times
kyky
2 years ago
A business impact analysis evaluates the criticality of systems and data, identifies potential risks, determines the potential loss or damage that could result from those risks, and helps prioritize security measures accordingly. It allows the analyst to understand the potential impact on confidentiality, integrity, and availability of the sensitive information contained in the existing applications.
upvoted 1 times
...
...
Tricee
2 years, 2 months ago
Selected Answer: C
A PCI Assessment is correct in this case. PCI Assessments make sure that organizations have processes and procedures in place to protect sensitive data.
upvoted 1 times
uday1985
1 year, 9 months ago
is it in the requirements of the question to be compliant ?
upvoted 1 times
...
...
2Fish
2 years, 3 months ago
Selected Answer: B
B. This is the only one that makes sense. C? We are not doing credit card transactions. and D? Overall, an application stress test is a critical component of software testing that helps ensure the application's performance, stability, and reliability under normal and extreme conditions. So I will stay with B
upvoted 1 times
...
catastrophie
2 years, 5 months ago
D. an application stress test. There is not a need for a BIA to be conducted. One is already documented for the business function at its current state and doesn't need to be completed repeatedly unless there has been a significant change such as recovering from a disaster/attack, or if there has been some type of big change to the technology like a new regulation or technology. Since the BIA is already in place, the newly developed application should be stress tested to ensure there are not vulnerabilities that would compromise the SPI when introduced to the environment.
upvoted 3 times
...
Frog_Man
2 years, 7 months ago
D - the business impact analysis would have already been completed by this stage. Stress testing is always done prior to go-live (production).
upvoted 3 times
...
MrRobotJ
2 years, 7 months ago
Selected Answer: D
I feel like it is too late to do BIA right before deployment...... just my two cents
upvoted 2 times
...
TheStudiousPeepz
2 years, 8 months ago
Selected Answer: B
Merc16 is spot on.
upvoted 1 times
...
R00ted
2 years, 8 months ago
Selected Answer: D
D is a good answer
upvoted 2 times
...
Tag
2 years, 8 months ago
Selected Answer: B
A business impact analysis (BIA) predicts the consequences of disruption of a business function and process and gathers information needed to develop recovery strategies. this is "prior" to deployment. application stress testing wouldve been done in a earlier stage of development and does not really seem to fit this scenario PCI and tabletop are definitely out
upvoted 3 times
Tag
2 years, 8 months ago
update, changed my answer to D seems i had the wrong idea
upvoted 1 times
...
...
Cizzla7049
2 years, 9 months ago
Selected Answer: D
D is correct
upvoted 1 times
Cizzla7049
2 years, 7 months ago
Changing to B. It's integrating with other apps handling SPI. A BIA is needed and to determine next steps in the event it damages functions of other apps.
upvoted 1 times
...
...
Ushouldkno
2 years, 9 months ago
Selected Answer: D
I'd go with D.
upvoted 2 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...