A security analyst is conducting a qualitative risk assessment for a critical internal web application. Which of the following core factors are primarily evaluated to determine the overall qualitative risk score? (Select TWO).
- The likelihood of a threat actor exploiting an application vulnerabilityCevap
- The operational and organizational impact if a threat event occursCevap
- CThe exact monetary Single Loss Expectancy (SLE) calculated from asset values
- DThe active inline packet filtering rules assigned to production honeypot systems
Cevap
The core factors evaluated during a qualitative risk assessment are the likelihood of a threat exploiting a vulnerability and the potential operational impact of that event.
Qualitative risk assessments determine overall risk severity by analyzing two primary variables: the likelihood (probability) that a vulnerability will be exploited and the impact (severity) of the resulting damage to the organization.
Adım Adım Çözüm
Anahtar Kavram
Qualitative Risk Assessment Factors (Likelihood vs. Impact)