GSEC · Question #24
An IT security manager is trying to quickly assess the risks associated with not implementing a corporate firewall system. What sort of risk assessment is most appropriate?
The correct answer is B. Qualitative risk assessment. A qualitative risk assessment uses descriptive ratings such as high, medium, and low rather than precise financial calculations, making it suitable for quick evaluations when exact data is unavailable.
Question
An IT security manager is trying to quickly assess the risks associated with not implementing a corporate firewall system. What sort of risk assessment is most appropriate?
Options
- AAnnualized Risk Assessment
- BQualitative risk assessment
- CQuantitative risk assessment
- DTechnical Risk Assessment
- EIterative Risk Assessment
How the community answered
(47 responses)- A4% (2)
- B79% (37)
- C2% (1)
- D11% (5)
- E4% (2)
Why each option
A qualitative risk assessment uses descriptive ratings such as high, medium, and low rather than precise financial calculations, making it suitable for quick evaluations when exact data is unavailable.
An Annualized Risk Assessment is a quantitative technique that calculates the Annualized Loss Expectancy (ALE) using hard numbers, requiring more time and detailed financial data than is implied by 'quickly assess'.
Qualitative risk assessment relies on expert judgment and subjective scales rather than hard financial figures, allowing a risk manager to quickly evaluate threats like the absence of a firewall without needing detailed cost data or actuarial calculations. It produces ratings based on likelihood and impact descriptors, which is efficient when time is limited and precise monetary values for assets and loss events are not readily available. This makes it the most appropriate approach for a rapid initial risk review.
Quantitative risk assessment assigns precise monetary values to assets and probabilities to threats, which is more rigorous and time-consuming than the quick assessment described in the scenario.
Technical Risk Assessment is not a formally recognized NIST or standard risk assessment category and does not describe the broad business-risk scope implied by the question.
Iterative Risk Assessment is not a standard risk assessment methodology recognized in frameworks such as NIST SP 800-30 or ISO 27005.
Concept tested: Qualitative vs quantitative risk assessment selection
Source: https://csrc.nist.gov/publications/detail/sp/800-30/rev-1/final
Topics
Community Discussion
No community discussion yet for this question.