200-201 Security Concepts Practice Question
A security analyst is evaluating risks and calculates that a threat has a likelihood of 0.5 and an impact of $200,000. What is the risk value?
⚠ Common exam trap
Cisco often tests the basic risk calculation formula (Risk = Likelihood × Impact) and the trap here is that candidates may mistakenly use the impact value alone or apply incorrect arithmetic, such as dividing instead of multiplying.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
$100,000
The risk value is calculated by multiplying the likelihood (0.5) by the impact ($200,000), resulting in $100,000. This is the standard quantitative risk analysis formula used in security assessments to prioritize threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
$50,000
Why it's wrong here
Multiplying likelihood by impact gives $100,000, so $50,000 misstates the arithmetic — it looks like impact halved, not the product. Single-loss expectancy is the correct calculation here; $50,000 would only arise if the likelihood were 0.25 against the same $200,000 impact.
- ✓
$100,000
Why this is correct
Multiplying likelihood (0.5) by impact ($200,000) yields $100,000, the quantitative risk value the analyst must report. This satisfies the stem's single-step calculation, giving the expected loss figure that feeds directly into the risk register and subsequent prioritisation decisions.
- ✗
$400,000
Why it's wrong here
$400,000 doubles the impact rather than applying the 0.5 likelihood. Risk value is likelihood multiplied by impact, giving $100,000. Doubling would apply if likelihood were 2.0, which is impossible since probabilities range from 0 to 1.
- ✗
$200,000
Why it's wrong here
$200,000 is the impact figure alone, ignoring the 0.5 likelihood entirely. Risk value derives from multiplying likelihood by impact, so quoting impact unchanged omits the probability weighting. Impact alone would be the relevant figure when assessing worst-case loss rather than expected risk.
Go deeper
Related to this question
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.