Which of the following is the ALE that Sara should report to management for a security breach?

Sara, a security analyst, is trying to prove to management what costs they could incur if their
customer database was breached. This database contains 250 records with PII. Studies
show that the cost per record for a breach is $300. The likelihood that their database would
be breached in the next year is only 5%. Which of the following is the ALE that Sara should
report to management for a security breach?

Sara, a security analyst, is trying to prove to management what costs they could incur if their
customer database was breached. This database contains 250 records with PII. Studies
show that the cost per record for a breach is $300. The likelihood that their database would
be breached in the next year is only 5%. Which of the following is the ALE that Sara should
report to management for a security breach?

A.
$1,500

B.
$3,750

C.
$15,000

D.
$75,000



Leave a Reply 3

Your email address will not be published. Required fields are marked *

5 × 1 =


Bright

Bright

Asset Value = 250 Records with PII
Exposure Factor = $300
ARO = 5%
Asset Value * Exposure factor = SLE
SLE * ARO = ALE
SLE = 75000
ARO = 5% = 5/100 = 0.05
ALE = 75000 * 0.05 = 3750.

Tony

Tony

A quick way with these questions for multiple choice is to ignore the zeros, since the zeros only give order of magnitude (eg 57 vs 5.7 vs 57000). So it’s 3*5*25, which is 375. The only answer starting 375 is B.

Bob

Bob

tony, you’re a genius. Thanks bro, saves so much work