Q: 9
A security analyst needs to ensure that systems across the organization are protected based on the
sensitivity of the content each system hosts. The analyst is working with the respective system
owners to help determine the best methodology that seeks to promote confidentiality, availability,
and integrity of the data being hosted. Which of the following should the security analyst perform
first to
categorize and prioritize the respective systems?
Options
Discussion
D makes sense since you need a baseline for asset value before you can apply the right controls or prioritize. Can't really rank systems by sensitivity if you don't know their importance. Pretty sure that's the intent here but happy if someone thinks otherwise.
Maybe D but sometimes asset value gets weird when systems are shared by multiple departments. I've seen similar questions where you actually have to clarify ownership first, but here I think prioritizing by value matches the exam logic.
Depends if the question is asking for the best first step or just any good practice. If it's best first, then D.
Be respectful. No spam.