Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 5 Question 7 Discussion

If a Business Analyst is asked to document the current state of the organization's web-based business environment, and recommend where cost savings could be realized, what risk factor must be included in the analysis?
C) Application Vulnerabilities
A) Organizational Risk Tolerance
B) Impact Severity
D) Threat Likelihood

IIBA-CCA Exam - Topic 5 Question 7 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 7
Topic #: 5
[All IIBA-CCA Questions]

If a Business Analyst is asked to document the current state of the organization's web-based business environment, and recommend where cost savings could be realized, what risk factor must be included in the analysis?

Show Suggested Answer Hide Answer
Suggested Answer: C

When analyzing a web-based business environment for potential cost savings, the Business Analyst must account for application vulnerabilities because they directly affect the organization's exposure to cyber attack and the true cost of operating a system. Vulnerabilities are weaknesses in application code, configuration, components, or dependencies that can be exploited to compromise confidentiality, integrity, or availability. In web environments, common examples include insecure authentication, injection flaws, broken access control, misconfigurations, outdated libraries, and weak session management.

Cost-saving recommendations frequently involve consolidating platforms, reducing tooling, lowering support effort, retiring controls, delaying upgrades, or moving to shared services. Without including known or likely vulnerabilities, the analysis can unintentionally recommend changes that reduce preventive and detective capability, increase attack surface, or extend the time vulnerabilities remain unpatched. Cybersecurity governance guidance emphasizes that technology rationalization must consider security posture: vulnerable applications often require additional controls (patching cadence, WAF rules, monitoring, code fixes, penetration testing, secure SDLC work) that carry ongoing cost. These costs are part of the system's ''total cost of ownership'' and should be weighed against proposed savings.

While impact severity and threat likelihood are important for overall risk scoring, the question asks what risk factor must be included when documenting the current state of a web-based environment. The most essential factor that ties directly to the environment's condition and drives remediation cost and exposure is application vulnerabilities.


Contribute your Thoughts:

0/2000 characters
Janella
14 days ago
I agree with Allene, but D) Threat Likelihood is also crucial. We need to know how likely threats are to impact savings.
upvoted 0 times
...
Allene
19 days ago
I lean towards C) Application Vulnerabilities. If we don't address vulnerabilities, cost savings could lead to bigger issues.
upvoted 0 times
...
Michal
24 days ago
I think it's A) Organizational Risk Tolerance. Understanding how much risk the organization can handle is key.
upvoted 0 times
...
Benton
29 days ago
Surprised no one mentioned the human factor in these risks!
upvoted 0 times
...
Tamie
1 month ago
B) Impact Severity is super important for understanding consequences.
upvoted 0 times
...
Zack
1 month ago
Wait, are we really considering D) Threat Likelihood? Seems a bit off.
upvoted 0 times
...
Aleta
3 months ago
I think A) Organizational Risk Tolerance is crucial too.
upvoted 0 times
...
Marnie
3 months ago
Definitely goes with C) Application Vulnerabilities. Can't ignore those!
upvoted 0 times
...
Annmarie
4 months ago
I lean towards D) Threat Likelihood because understanding the chances of threats is key in identifying cost-saving opportunities.
upvoted 0 times
...
Maybelle
4 months ago
I practiced a question similar to this, and I feel like C) Application Vulnerabilities might be crucial since we're talking about a web-based environment.
upvoted 0 times
...
Laticia
4 months ago
I'm not entirely sure, but I remember something about assessing potential impacts, so B) Impact Severity could be relevant too.
upvoted 0 times
...
Wenona
4 months ago
I think the risk factor that should be included is definitely related to how the organization views risk, so maybe A) Organizational Risk Tolerance?
upvoted 0 times
...

Save Cancel