Courseiva

CAS-004 Governance, Risk, and Compliance Practice Question

A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?

⚠ Common exam trap

CAS-005 often tests the qualitative-vs-quantitative tradeoff, so candidates who assume FAIR is 'easier' or 'more communicable' pick the wrong advantage — the real advantage is monetary output for ROI.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

FAIR provides a monetary value for risk, enabling ROI calculations

FAIR (Factor Analysis of Information Risk) is a quantitative risk framework that expresses risk in monetary terms — typically annualized loss expectancy (ALE) derived from loss event frequency and loss magnitude. This monetary output enables direct ROI calculations for security investments and lets leadership compare cyber risk against other business risks in financial terms.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    FAIR is the only framework recognized by NIST

    Why it's wrong here

    FAIR is not a NIST-recognised framework; NIST does not endorse it as the sole standard, so the claim is factually false. It tempts because NIST publications do reference FAIR within risk-assessment guidance, and candidates conflate citation with formal recognition. FAIR's actual advantage is expressing loss exposure in monetary terms, unlike ordinal heat-map ratings.

  • ✗

    FAIR is easier to communicate to non-technical stakeholders

    Why it's wrong here

    FAIR's reliance on probabilistic modelling and financial quantification can initially present a steeper learning curve for non-technical stakeholders compared to the immediate visual simplicity of a qualitative heat map. Heat maps offer instant, high-level risk categorisation without requiring an understanding of underlying calculations. However, FAIR is designed to translate complex technical risks into a common financial language, making it highly effective for justifying risk treatment investments and prioritising actions based on tangible monetary impact once the methodology is grasped.

  • ✗

    FAIR requires less data and expertise to implement

    Why it's wrong here

    FAIR demands more data and modelling expertise than a heat map, so this reverses the actual trade-off. It tempts because qualitative heat maps genuinely need minimal input, making them the pragmatic pick for quick triage or low-maturity programmes where calibrated loss estimates are unavailable.

  • ✓

    FAIR provides a monetary value for risk, enabling ROI calculations

    Why this is correct

    FAIR quantifies risk in monetary terms by modelling loss event frequency and loss magnitude, producing annualised loss exposure. This contrasts with qualitative heat maps that rank risks ordinally, and enables cost-benefit and ROI comparisons of proposed security controls.

About these practice questions

Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.