A security analyst is conducting a qualitative risk assessment for a critical internal web application. Which of the following core factors are primarily evaluated to determine the overall qualitative risk score? (Select TWO).
- The likelihood of a threat actor exploiting an application vulnerabilityAnswer
- The operational and organizational impact if a threat event occursAnswer
- CThe exact monetary Single Loss Expectancy (SLE) calculated from asset values
- DThe active inline packet filtering rules assigned to production honeypot systems
Answer
The core factors evaluated during a qualitative risk assessment are the likelihood of a threat exploiting a vulnerability and the potential operational impact of that event.
Qualitative risk assessments determine overall risk severity by analyzing two primary variables: the likelihood (probability) that a vulnerability will be exploited and the impact (severity) of the resulting damage to the organization.
Step-by-Step Solution
Key Concept
Qualitative Risk Assessment Factors (Likelihood vs. Impact)