Question

Difficulty: EasyRisk Identification, Assessment, and Response Strategies

A security analyst is conducting a qualitative risk assessment for a critical internal web application. Which of the following core factors are primarily evaluated to determine the overall qualitative risk score? (Select TWO).

  1. The likelihood of a threat actor exploiting an application vulnerabilityAnswer
  2. The operational and organizational impact if a threat event occursAnswer
  3. C
    The exact monetary Single Loss Expectancy (SLE) calculated from asset values
  4. D
    The active inline packet filtering rules assigned to production honeypot systems

Answer

The core factors evaluated during a qualitative risk assessment are the likelihood of a threat exploiting a vulnerability and the potential operational impact of that event.
Qualitative risk assessments determine overall risk severity by analyzing two primary variables: the likelihood (probability) that a vulnerability will be exploited and the impact (severity) of the resulting damage to the organization.

Step-by-Step Solution

1
Identify the primary parameters used in qualitative risk rating scales.
Qualitative risk analysis assigns subjective categories (such as High, Medium, Low) based on Likelihood and Impact.
Risk is fundamentally calculated as a function of the probability of an incident (Likelihood) and the resulting damage (Impact).
2
Differentiate qualitative factors from quantitative metrics and specific defensive controls.
Exact financial calculations like Single Loss Expectancy (SLE) belong to quantitative risk assessments, while honeypots represent specialized security controls.
Qualitative metrics intentionally avoid precise financial figures and specific operational control parameters.

Key Concept

Qualitative Risk Assessment Factors (Likelihood vs. Impact)
Rate this question