CAS-004 Governance, Risk, and Compliance Practice Question
A security manager is evaluating two risk quantification approaches: Factor Analysis of Information Risk (FAIR) and a qualitative heat map. Which of the following is a key advantage of using FAIR over the qualitative heat map?
⚠ Common exam trap
CAS-005 often tests the qualitative-vs-quantitative tradeoff, so candidates who assume FAIR is 'easier' or 'more communicable' pick the wrong advantage — the real advantage is monetary output for ROI.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
FAIR provides a monetary value for risk, enabling ROI calculations
FAIR (Factor Analysis of Information Risk) is a quantitative risk framework that expresses risk in monetary terms — typically annualized loss expectancy (ALE) derived from loss event frequency and loss magnitude. This monetary output enables direct ROI calculations for security investments and lets leadership compare cyber risk against other business risks in financial terms.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
FAIR is the only framework recognized by NIST
Why it's wrong here
FAIR is not a NIST-recognised framework; NIST does not endorse it as the sole standard, so the claim is factually false. It tempts because NIST publications do reference FAIR within risk-assessment guidance, and candidates conflate citation with formal recognition. FAIR's actual advantage is expressing loss exposure in monetary terms, unlike ordinal heat-map ratings.
- ✗
FAIR is easier to communicate to non-technical stakeholders
Why it's wrong here
FAIR's reliance on probabilistic modelling and financial quantification can initially present a steeper learning curve for non-technical stakeholders compared to the immediate visual simplicity of a qualitative heat map. Heat maps offer instant, high-level risk categorisation without requiring an understanding of underlying calculations. However, FAIR is designed to translate complex technical risks into a common financial language, making it highly effective for justifying risk treatment investments and prioritising actions based on tangible monetary impact once the methodology is grasped.
- ✗
FAIR requires less data and expertise to implement
Why it's wrong here
FAIR demands more data and modelling expertise than a heat map, so this reverses the actual trade-off. It tempts because qualitative heat maps genuinely need minimal input, making them the pragmatic pick for quick triage or low-maturity programmes where calibrated loss estimates are unavailable.
- ✓
FAIR provides a monetary value for risk, enabling ROI calculations
Why this is correct
FAIR quantifies risk in monetary terms by modelling loss event frequency and loss magnitude, producing annualised loss exposure. This contrasts with qualitative heat maps that rank risks ordinally, and enables cost-benefit and ROI comparisons of proposed security controls.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CAS-005 question from scratch — 973 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.