CCSP · Question #363
During the assessment phase of a risk evaluation, what are the two types of tests that are performed? Response:
The correct answer is D. Qualitative and quantitative. During the assessment phase of a risk evaluation, both qualitative and quantitative tests are performed to evaluate risks. Qualitative assessments involve descriptive analysis, while quantitative assessments use numerical values to measure risk.
Question
During the assessment phase of a risk evaluation, what are the two types of tests that are performed? Response:
Options
- AInternal and external
- BTechnical and managerial
- CPhysical and logical
- DQualitative and quantitative
How the community answered
(40 responses)- A3% (1)
- B3% (1)
- D95% (38)
Why each option
During the assessment phase of a risk evaluation, both qualitative and quantitative tests are performed to evaluate risks. Qualitative assessments involve descriptive analysis, while quantitative assessments use numerical values to measure risk.
Internal and external are perspectives from which an assessment might be performed, not the types of tests themselves.
Technical and managerial refer to types of controls or aspects of a security program, not the methods of risk assessment.
Physical and logical refer to types of security controls or assets being protected, not the methodologies for risk assessment.
The two primary types of tests or analyses performed during the risk assessment phase are qualitative and quantitative. Qualitative risk assessment prioritizes risks based on subjective impact and likelihood, while quantitative risk assessment assigns numerical values to risk factors, enabling detailed cost-benefit analysis and impact calculation.
Concept tested: Risk assessment methodologies
Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-assessment
Topics
Community Discussion
No community discussion yet for this question.