Q: 9
A security analyst needs to ensure that systems across the organization are protected based on the
sensitivity of the content each system hosts. The analyst is working with the respective system
owners to help determine the best methodology that seeks to promote confidentiality, availability,
and integrity of the data being hosted. Which of the following should the security analyst perform
first to
categorize and prioritize the respective systems?
Options
Discussion
Option D makes sense here, since you can't really categorize or prioritize protection if you don't know the value or criticality of each system. A is tempting but that comes after asset valuation. Pretty sure that's how CYSA+ expects you to approach it, but let me know if you see it differently.
Option D is what I'd pick. Determining asset value always comes first since you can't really prioritize protection or choose controls without knowing what's most important to the business. Pretty standard risk management step, I think. If anyone has seen a question twist where A makes more sense, let me know.
D makes sense since you need a baseline for asset value before you can apply the right controls or prioritize. Can't really rank systems by sensitivity if you don't know their importance. Pretty sure that's the intent here but happy if someone thinks otherwise.
Probably D, seen exam guides and official practice refer to determining asset value as the first thing in prioritizing systems.
D , saw similar in practice sets and it's always asset value first for prioritization.
C or D
I was thinking C at first since alerts help with new threats, but now I'm realizing D makes more sense for prioritizing. Still, pretty sure some exam reports mention C in a similar scenario so not 100% sure.
I was thinking C at first since alerts help with new threats, but now I'm realizing D makes more sense for prioritizing. Still, pretty sure some exam reports mention C in a similar scenario so not 100% sure.
A or maybe B, not convinced D is first without knowing user needs.
D that's the first step for risk-based prioritization. You can't rank protection without knowing asset value. Anyone see it another way?
Had something like this in a mock, it's D.
I don't think it's D right away. Option A is tempting since interviewing users might give you real context first.
Be respectful. No spam.