CASP+ CAS-003 – Question 265


A Chief Information Security Officer (CISO) needs to establish a KRI for a particular system. The system holds archives of contracts that are no longer in use. The contracts contain intellectual property and have a data classification of nonpublic. Which of the following be the BEST risk indicator for this system?

A. Average minutes of downtime per quarter
B. Percent of patches applied in the past 30 days
C. Count of login failures per week
D. Number of accounts accessing the system per day

Correct Answer: D