Skip to content
CAS-005
Governance, Risk, and Compliance
hard
Question 2 of 20

An organization's security team has completed a quantitative risk assessment. The ALE for a specific threat scenario is $500,000. A proposed control costs $600,000 annually to implement. What is the MOST appropriate recommendation?

AImplement the control because the threat scenario is high severity
BDo not implement the control because its annual cost exceeds the ALE
CImplement the control and negotiate a lower cost with the vendor
DEscalate to the board because ALE calculations are unreliable

Educational Content — CertQnA practice questions are written against official exam objectives, covering the same domains tested on the real exam. All content is original and independent — not actual exam questions, not affiliated with any certification vendor. Learn more about our content policy

Discussion

Be the first to share your understanding of this concept

⚠️ Discussion is for concept clarification only. Do not share or request actual exam questions or answers.

Sign in to join the discussion