CompTIA SecurityX CAS-005 (V5) Practice Question

During a risk evaluation of core information systems, the team decides to ignore any scenario involving a severe, organization-wide outage because such events are considered unlikely. Which of the following is the most probable consequence of leaving these high-impact scenarios out of the analysis?

  • It will automatically assign a HIGH rating to every identified risk, inflating overall remediation costs.

  • It has no effect on the final risk rating because low-probability events are discounted by default.

  • It guarantees compliance with NIST SP 800-30 by focusing the assessment scope on realistic events only.

  • It can cause the organization to underestimate impact severity, leading to inadequate prioritization and funding of mitigation efforts.

CompTIA SecurityX CAS-005 (V5)
Governance, Risk, and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $64
$529.00 $465.00
SAVE $70
CompTIA SecurityX Voucher with Retake
v5 / CAS-005
Includes Retake
$578.00 $508.00
Bash, the Crucial Exams Chat Bot
AI Bot