CompTIA CASP+ (CAS-003) — Question 281

An infrastructure team is at the end of a procurement process and has selected a vendor. As part of the final negotiation, there are a number of outstanding issues, including:
1. Indemnity clauses have identified the maximum liability.
2. The data will be hosted and managed outside of the company's geographical location.
The number of users accessing the system will be small, and no sensitive data will be hosted in the solution. As the security consultant of the project, which of the following should the project's security consultant recommend as the NEXT step?

Answer options

Correct answer: B

Explanation

The correct answer is B, as requiring the solution owner to accept the identified risks is appropriate in this context, given that the data is not sensitive and the user base is small. Option A is incorrect because a security exemption may not be necessary in this case. Option C does not address the immediate need for risk acceptance, while option D focuses on past actions rather than current negotiations.