CSA (312-39) SOC Simulation Lab

In this scenario, you will apply standard risk management formulas to triage and prioritize competing SIEM alerts. You will learn how Likelihood, Impact, and Asset Value combine to determine the true severity of a potential incident.

Scenario Context

You are working alongside Lisa Carter, a SOC analyst at a major financial services firm. The SOC is currently experiencing an alert spike, with multiple SIEM notables firing simultaneously. You cannot investigate everything at once.

To prioritize response efforts, Lisa relies on the organization's SOAR platform, which enriches incoming alerts with threat intelligence (Likelihood), business impact analysis (Impact), and CMDB data (Asset Value) to calculate a final Risk Score.

Security Environment

The SOAR platform displays the current triage queue waiting for Lisa's assignment. Notice how the three variables map to the alerts:

INC-9901 | Title: Suspected Ransomware Activity (CrowdStrike) ↳ Threat Intel: Campaign: FIN7 | Likelihood: HIGH (Active IOCs confirmed) ↳ CMDB Data: Asset: DB-PROD-CUST-01 | Value: HIGH (PCI/Customer Data) ↳ BIA Matrix: Business Impact: HIGH (Tier 1 Core Banking App) ↳ Status: Pending Risk Calculation INC-9902 | Title: Brute Force Attempt (AWS WAF) ↳ Threat Intel: Source: Botnet IP | Likelihood: LOW (WAF is actively blocking) ↳ CMDB Data: Asset: DEV-TEST-WEB | Value: LOW (Sanitized test data) ↳ BIA Matrix: Business Impact: LOW (Non-critical sandbox) ↳ Status: Pending Risk Calculation

Question

Lisa Carter, a SOC analyst at a financial services firm, is performing a risk assessment following a series of suspicious alerts detected by the SIEM (Security Information and Event Management) system. Her task is to evaluate the risk of a potential data breach prioritizing incident response efforts. She assesses three key factors: the likelihood of an attack succeeding based on current threat intelligence, the impact on critical business operations if the breach occurs, and the value of the assets targeted (e.g., customer data, financial systems). Using the standard risk assessment formula, which of the following scenarios represents the highest risk to the organization?
SOC Hint: In quantitative risk assessments, Risk is calculated as a product of its factors (Risk = Likelihood × Impact × Asset Value). Which combination mathematically yields the largest result?