CompTIA SecurityX CAS-005 (V5) Practice Question

During a risk evaluation of core information systems, the team decides to ignore any scenario involving a severe, organization-wide outage because such events are considered unlikely. Which of the following is the most probable consequence of leaving these high-impact scenarios out of the analysis?

  • It has no effect on the final risk rating because low-probability events are discounted by default.

  • It can cause the organization to underestimate impact severity, leading to inadequate prioritization and funding of mitigation efforts.

  • It guarantees compliance with NIST SP 800-30 by focusing the assessment scope on realistic events only.

  • It will automatically assign a HIGH rating to every identified risk, inflating overall remediation costs.

CompTIA SecurityX CAS-005 (V5)
Governance, Risk, and Compliance
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

SAVE $64
$529.00 $465.00
SAVE $70
CompTIA SecurityX Voucher with Retake
v5 / CAS-005
Includes Retake
$578.00 $508.00
Bash, the Crucial Exams Chat Bot
AI Bot