nerdexam
(ISC)2

CCSP · Question #363

During the assessment phase of a risk evaluation, what are the two types of tests that are performed? Response:

The correct answer is D. Qualitative and quantitative. During the assessment phase of a risk evaluation, both qualitative and quantitative tests are performed to evaluate risks. Qualitative assessments involve descriptive analysis, while quantitative assessments use numerical values to measure risk.

Submitted by lucia.co· Apr 18, 2026Legal, Risk and Compliance

Question

During the assessment phase of a risk evaluation, what are the two types of tests that are performed? Response:

Options

  • AInternal and external
  • BTechnical and managerial
  • CPhysical and logical
  • DQualitative and quantitative

How the community answered

(40 responses)
  • A
    3% (1)
  • B
    3% (1)
  • D
    95% (38)

Why each option

During the assessment phase of a risk evaluation, both qualitative and quantitative tests are performed to evaluate risks. Qualitative assessments involve descriptive analysis, while quantitative assessments use numerical values to measure risk.

AInternal and external

Internal and external are perspectives from which an assessment might be performed, not the types of tests themselves.

BTechnical and managerial

Technical and managerial refer to types of controls or aspects of a security program, not the methods of risk assessment.

CPhysical and logical

Physical and logical refer to types of security controls or assets being protected, not the methodologies for risk assessment.

DQualitative and quantitativeCorrect

The two primary types of tests or analyses performed during the risk assessment phase are qualitative and quantitative. Qualitative risk assessment prioritizes risks based on subjective impact and likelihood, while quantitative risk assessment assigns numerical values to risk factors, enabling detailed cost-benefit analysis and impact calculation.

Concept tested: Risk assessment methodologies

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-assessment

Topics

#Risk assessment#Qualitative analysis#Quantitative analysis#Risk evaluation

Community Discussion

No community discussion yet for this question.

Full CCSP Practice