U.S. Independence Day Deal! Unlock 25% OFF Today – Limited-Time Offer - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 5 Question 7 Discussion

If a Business Analyst is asked to document the current state of the organization's web-based business environment, and recommend where cost savings could be realized, what risk factor must be included in the analysis?
C) Application Vulnerabilities
A) Organizational Risk Tolerance
B) Impact Severity
D) Threat Likelihood

IIBA-CCA Exam - Topic 5 Question 7 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 7
Topic #: 5
[All IIBA-CCA Questions]

If a Business Analyst is asked to document the current state of the organization's web-based business environment, and recommend where cost savings could be realized, what risk factor must be included in the analysis?

Show Suggested Answer Hide Answer
Suggested Answer: C

When analyzing a web-based business environment for potential cost savings, the Business Analyst must account for application vulnerabilities because they directly affect the organization's exposure to cyber attack and the true cost of operating a system. Vulnerabilities are weaknesses in application code, configuration, components, or dependencies that can be exploited to compromise confidentiality, integrity, or availability. In web environments, common examples include insecure authentication, injection flaws, broken access control, misconfigurations, outdated libraries, and weak session management.

Cost-saving recommendations frequently involve consolidating platforms, reducing tooling, lowering support effort, retiring controls, delaying upgrades, or moving to shared services. Without including known or likely vulnerabilities, the analysis can unintentionally recommend changes that reduce preventive and detective capability, increase attack surface, or extend the time vulnerabilities remain unpatched. Cybersecurity governance guidance emphasizes that technology rationalization must consider security posture: vulnerable applications often require additional controls (patching cadence, WAF rules, monitoring, code fixes, penetration testing, secure SDLC work) that carry ongoing cost. These costs are part of the system's ''total cost of ownership'' and should be weighed against proposed savings.

While impact severity and threat likelihood are important for overall risk scoring, the question asks what risk factor must be included when documenting the current state of a web-based environment. The most essential factor that ties directly to the environment's condition and drives remediation cost and exposure is application vulnerabilities.


Contribute your Thoughts:

0/2000 characters
Aleta
1 month ago
I think A) Organizational Risk Tolerance is crucial too.
upvoted 0 times
...
Marnie
2 months ago
Definitely goes with C) Application Vulnerabilities. Can't ignore those!
upvoted 0 times
...
Annmarie
2 months ago
I lean towards D) Threat Likelihood because understanding the chances of threats is key in identifying cost-saving opportunities.
upvoted 0 times
...
Maybelle
2 months ago
I practiced a question similar to this, and I feel like C) Application Vulnerabilities might be crucial since we're talking about a web-based environment.
upvoted 0 times
...
Laticia
3 months ago
I'm not entirely sure, but I remember something about assessing potential impacts, so B) Impact Severity could be relevant too.
upvoted 0 times
...
Wenona
3 months ago
I think the risk factor that should be included is definitely related to how the organization views risk, so maybe A) Organizational Risk Tolerance?
upvoted 0 times
...

Save Cancel