Pre-Summer Special Limited Time 70% Discount Offer - Ends in 0d 00h 00m 00s - Coupon code: validbest

Exam CAS-004 All Questions
Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

CompTIA CASP CAS-004 Question # 167 Topic 17 Discussion

CAS-004 Exam Topic 17 Question 167 Discussion:
Question #: 167
Topic #: 17

An organization is assessing the security posture of a new SaaS CRM system that handles sensitive PI I and identity information, such as passport numbers. The SaaS CRM system does not meet the organization's current security standards. The assessment identifies the following:

1) There will be a 520,000 per day revenue loss for each day the system is delayed going into production.

2) The inherent risk is high.

3) The residual risk is low.

4) There will be a staged deployment to the solution rollout to the contact center.

Which of the following risk-handling techniques will BEST meet the organization's requirements?


A.

Apply for a security exemption, as the risk is too high to accept.


B.

Transfer the risk to the SaaS CRM vendor, as the organization is using a cloud service.


C.

Accept the risk, as compensating controls have been implemented to manage the risk.


D.

Avoid the risk by accepting the shared responsibility model with the SaaS CRM provider.


Get Premium CAS-004 Questions

Contribute your Thoughts:


Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.