Which of the following is a qualitative approach to risk ana - CompTIA Security+ SY0-701

Question

Which of the following is a qualitative approach to risk analysis?
 

Answers
  1. correct
Explanation

Correct Answer: C. Assigning a level of high, medium, or low to the risk rating. Qualitative risk analysis focuses on subjective, descriptive assessments of risks rather than numerical calculations. Assigning risk levels such as “high,” “medium,” or “low” is a clear example of this approach. These labels are based on expert judgment, interviews, or workshops rather than strict statistical data. Organizations often use this method when exact numerical data is unavailable or when quick prioritization is needed. The process emphasizes relative severity and likelihood, enabling decision-makers to focus resources on the most pressing risks without needing detailed calculations. While it lacks precision compared to quantitative methods, qualitative analysis is valuable for creating accessible and actionable assessments, especially for nontechnical stakeholders. It is commonly used in initial stages of risk management, often in the form of heat maps or risk matrices, to visually communicate risk levels across the organization. This makes it an essential component of comprehensive risk analysis.

Why Other Options are Incorrect:

  • A. Including the MTTR and MTBF as part of the risk assessment is quantitative because MTTR (Mean Time to Repair) and MTBF (Mean Time Between Failures) are measurable, numerical metrics.

  • B. Tracking and documenting network risks using a risk register is an organizational tool for risk management, but it does not inherently qualify as qualitative unless risks are assigned subjective ratings. By itself, it’s simply recordkeeping.

  • D. Using ALE and ARO to help determine whether a risk should be mitigated is quantitative because ALE (Annualized Loss Expectancy) and ARO (Annualized Rate of Occurrence) rely on numerical calculations to estimate financial impact and frequency of risks.

No Payment Cards Needed

Related Courses

Discover a range of courses designed to provide you with the knowledge and skills needed to excel in your chosen field.

a prepsaret exam featured image
CompTIA Prep

220-1201 - CompTIA A+ Exam Core 1

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

220-1202 - CompTIA A+ Exam Core 2

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA SecurityX CAS-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud Essentials+ CLO-002

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Network+ N10-009

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Data + DA0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Pentest+

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Linux+ XK0-005

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA CySA+ CSO-003

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA DataSys+ DS0-001

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Tech+ FC0-U71

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Cloud+ CV0-004

Start Course Prep
a prepsaret exam featured image
CompTIA Prep

CompTIA Server+ SK0-005

Start Course Prep

Easy way to pass your test within a week with prepsaret

You don’t need one month to study and pass your test.
With Prepsaret, it takes you a few days to grasp all the concepts needed to pass your exams

View Courses Offered