nerdexam
(ISC)2

SSCP · Question #1245

When compiling a risk assessment report, which of the following items should be included? (Choose all that apply)

The correct answer is A. Vulnerability levels D. Data sensitivity levels E. ALE calculations. A comprehensive risk assessment report should include vulnerability levels, data sensitivity classifications, and Annualized Loss Expectancy (ALE) calculations to effectively evaluate and present risks.

Submitted by yousef_jo· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

When compiling a risk assessment report, which of the following items should be included? (Choose all that apply)

Options

  • AVulnerability levels
  • BMethod of attack used
  • CNames of frequent security violators
  • DData sensitivity levels
  • EALE calculations

How the community answered

(19 responses)
  • A
    89% (17)
  • B
    5% (1)
  • C
    5% (1)

Why each option

A comprehensive risk assessment report should include vulnerability levels, data sensitivity classifications, and Annualized Loss Expectancy (ALE) calculations to effectively evaluate and present risks.

AVulnerability levelsCorrect

Vulnerability levels are essential for a risk assessment report, as they identify the weaknesses that could be exploited and contribute to calculating the likelihood of a risk event.

BMethod of attack used

While knowledge of attack methods is part of identifying threats, a risk assessment report typically focuses on the *potential* for attack, vulnerabilities, and impact, rather than detailing specific methods *used* in past attacks, which would be part of an incident report or threat intelligence.

CNames of frequent security violators

Including names of frequent security violators in a public or widely distributed risk assessment report is generally not appropriate, as it can raise privacy concerns and is typically handled through internal HR or disciplinary processes, not in the risk assessment itself.

DData sensitivity levelsCorrect

Data sensitivity levels are crucial for a risk assessment report because the potential impact of a security incident depends heavily on the classification and importance of the data involved.

EALE calculationsCorrect

ALE (Annualized Loss Expectancy) calculations provide a quantitative measure of the financial impact of a risk over a year, making them a key component for prioritizing risks in a report.

Concept tested: Risk assessment report components

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/risk-management

Topics

#Risk Assessment#Risk Report#Vulnerability Analysis#Quantitative Risk

Community Discussion

No community discussion yet for this question.

Full SSCP Practice