nerdexam
(ISC)2(ISC)2

CSSLP · Question #42

CSSLP Question #42: Real Exam Question with Answer & Explanation

The correct answer is C: A qualitative risk analysis requires accurate and unbiased data if it is to be credible.. This question addresses the crucial data quality requirements for conducting a credible qualitative risk analysis in project management.

Secure Software Lifecycle Management

Question

You are the project manager of the CUL project in your organization. You and the project team are assessing the risk events and creating a probability and impact matrix for the identified risks. Which one of the following statements best describes the requirements for the data type used in qualitative risk analysis?

Options

  • AA qualitative risk analysis encourages biased data to reveal risk tolerances.
  • BA qualitative risk analysis required unbiased stakeholders with biased risk tolerances.
  • CA qualitative risk analysis requires accurate and unbiased data if it is to be credible.
  • DA qualitative risk analysis requires fast and simple data to complete the analysis.

Explanation

This question addresses the crucial data quality requirements for conducting a credible qualitative risk analysis in project management.

Common mistakes.

  • A. A qualitative risk analysis aims to provide an objective assessment of risks, and therefore, it actively discourages biased data, as bias would compromise the integrity and usefulness of the analysis.
  • B. While stakeholders have varying risk tolerances, the data used in the analysis should strive for impartiality; requiring 'biased risk tolerances' for the data itself is incorrect as it would undermine the assessment's validity.
  • D. While obtaining fast and simple data can be desirable for efficiency, the primary requirement for a credible qualitative risk analysis is the accuracy and lack of bias in the data, not just its speed or simplicity.

Concept tested. Qualitative risk analysis data requirements

Reference. https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-30r1.pdf

Topics

#Risk Management#Qualitative Risk Analysis#Data Quality#SSDLC Risk

Community Discussion

No community discussion yet for this question.

Full CSSLP PracticeBrowse All CSSLP Questions