200-201 Question 192
Select 3A cybersecurity analyst at a company is performing an inventory of the organization's assets. Which of the following should be considered critical assets to prioritize during this process?
- A
The organization’s customer database containing personally identifiable information (PII)
- B
The office coffee machine connected to the corporate Wi-Fi network
- C
The company’s financial records stored on a secure server
- D
The CEO’s personal mobile device used for accessing corporate emails
- E
A public-facing company website hosted on an external provider
- F
Obsolete hardware stored in a warehouse with no network connectivity
Show answer and explanation
Correct answers: A, C, D
Explanation
Critical assets are those that are essential to the organization's operations, contain sensitive information, or could cause significant business impact if compromised. The customer database, financial records, and the CEO's mobile device all fit this description, making them a priority for inventory and protection.
- A. Correct.
The customer database containing PII is a critical asset because it holds sensitive and valuable information. Its compromise could lead to data breaches and regulatory penalties.
- B. Incorrect.
While the coffee machine is connected to the network, it is not typically considered a critical asset unless it poses a significant security risk, which is not specified in this scenario.
- C. Correct.
The company’s financial records are critical assets as they are essential for business operations and contain confidential information.
- D. Correct.
The CEO’s personal mobile device is a critical asset because it is used to access corporate emails and may contain sensitive company information.
- E. Incorrect.
The public-facing website, while important for the organization’s online presence, is typically considered less critical compared to other assets unless it is directly tied to sensitive data or core business operations.
- F. Incorrect.
Obsolete hardware with no network connectivity is not a critical asset as it does not pose an immediate cybersecurity risk or hold valuable information.