PrepAway - Latest Free Exam Questions & Answers

What type of risk analysis approach does the following graphic provide?

What type of risk analysis approach does the following graphic provide?

PrepAway - Latest Free Exam Questions & Answers

A.
Quantitative

B.
Qualitative

C.
Operationally Correct

D.
Operationally Critical

Explanation:
B: A qualitative risk analysis approach does not assign monetary values to components and losses. Instead, qualitative methods walk through different scenarios of risk
possibilities and rank the seriousness of the threats and the validity of the different possible countermeasures based on opinions. Qualitative analysis techniques include
judgment, best practices, intuition, and experience. This graphic shows a rating system, which qualitative risk analysis uses instead of percentages and monetary numbers.
A is incorrect because a quantitative risk analysis attempts to assign percentages and monetary values to all elements of the risk analysis process. These elements may
include safeguard costs, asset value, business impact, threat frequency, safeguard effectiveness, exploit probabilities, and so on. When all of these are quantified, the process is
said to be quantitative. Each element within the analysis (asset value, threat frequency, severity of vulnerability, impact damage, safeguard costs, safeguard effectiveness,
uncertainty, and probability items) is quantified and entered into equations to determine total and residual risks.
C is incorrect because there is no Operationally Correct formal risk analysis approach. This is a distracter answer.
D is incorrect because there is no formal Operationally Critical risk analysis approach. This is a distracted answer.


Leave a Reply