CompTIA CASP+ (CAS-004) — Question 607

A security analyst is participating in a risk assessment and is helping to calculate the exposure factor associated with various systems and processes within the organization. Which of the following resources would be most useful to calculate the exposure factor in this scenario?

Answer options

Correct answer: B

Explanation

The correct answer is B, as a Business Impact Analysis (BIA) provides insights into the potential effects of disruptions to business operations, which is crucial for calculating the exposure factor. The other options, such as gap analysis and risk register, do not specifically focus on the financial or operational impacts needed for this calculation.