nerdexam
(ISC)2

CISSP-ISSAP · Question #62

Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?

The correct answer is B. Annualized Rate of Occurrence (ARO). Annualized Rate of Occurrence (ARO) is the metric that quantifies how many times per year a specific threat is expected to occur - for example, an ARO of 0.5 means the threat is expected once every two years. A Safeguard (A) is a countermeasure used to reduce risk, not a…

Architect for Governance, Risk, and Compliance

Question

Which of the following terms related to risk management represents the estimated frequency at which a threat is expected to occur?

Options

  • ASafeguard
  • BAnnualized Rate of Occurrence (ARO)
  • CSingle Loss Expectancy (SLE)
  • DExposure Factor (EF)

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    88% (29)
  • C
    3% (1)
  • D
    6% (2)

Explanation

Annualized Rate of Occurrence (ARO) is the metric that quantifies how many times per year a specific threat is expected to occur - for example, an ARO of 0.5 means the threat is expected once every two years. A Safeguard (A) is a countermeasure used to reduce risk, not a measurement of frequency. Single Loss Expectancy (SLE) (C) represents the monetary loss from a single incident (Asset Value × Exposure Factor), while Exposure Factor (EF) (D) is the percentage of an asset's value lost in a single incident - both deal with dollar impact, not frequency. ARO is used alongside SLE to calculate Annualized Loss Expectancy (ALE = SLE × ARO), which is the key formula to remember: ARO is the rate (how often), SLE is the cost (how much per event), and ALE is the total yearly expected loss.

Memory tip: Think of ARO as your "annual odds" - just like a weather forecast gives you the probability of rain per year, ARO gives you the expected number of threat occurrences per year.

Topics

#Annualized Rate of Occurrence#Risk Quantification#Threat Frequency

Community Discussion

No community discussion yet for this question.

Full CISSP-ISSAP Practice