Courseiva
Security Concepts →mediumMultiple Choice

200-201 Security Concepts Practice Question

A security analyst is evaluating the risk of a new web application that will store customer credit card data. The analyst needs to determine the likelihood and impact of a data breach. Which risk analysis approach involves assigning numerical values to assets, threats, and vulnerabilities to calculate an annualized loss expectancy (ALE)?

⚠ Common exam trap

The trap here is assuming that any risk analysis producing a high/medium/low rating is sufficient, when ALE specifically requires quantitative inputs.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Quantitative risk analysis

Quantitative risk analysis uses numerical values for assets, threats, and vulnerabilities to calculate annualized loss expectancy, enabling cost-benefit comparisons for security investments. Qualitative analysis uses descriptive ratings, while BIA and threat modeling serve different purposes. For credit card data, the quantitative approach provides the financial justification for controls.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Quantitative risk analysis

    Why this is correct

    Quantitative risk analysis assigns monetary and numeric values to assets, threat frequency, and vulnerability likelihood to compute metrics like single loss expectancy (SLE) and annualized loss expectancy (ALE). This allows the analyst to justify security spending by comparing expected losses against control costs. For credit card data, the analyst would estimate the value of the data, the probability of a breach, and the potential financial impact.

  • ✗

    Qualitative risk analysis

    Why it's wrong here

    Qualitative risk analysis uses descriptive scales such as high, medium, and low rather than numerical values. It is useful for prioritizing risks when precise data is unavailable, but it does not calculate annualized loss expectancy. For a web application storing credit card data, a qualitative approach might rank the risk as high, but it would not produce the quantitative financial figures needed for a cost-benefit analysis of security controls.

  • ✗

    Threat modeling

    Why it's wrong here

    Threat modeling is a structured approach to identifying potential threats and vulnerabilities in a system design, often using frameworks like STRIDE or PASTA. It helps prioritize security requirements but does not produce numerical loss expectancies. For the web application scenario, threat modeling would help identify attack vectors, but it would not give the CIO the ALE figure needed to compare the cost of controls against potential breach losses.

  • ✗

    Business impact analysis (BIA)

    Why it's wrong here

    A business impact analysis focuses on identifying critical business functions and determining the effects of disruptions, including recovery time and recovery point objectives. While it informs risk management, it does not calculate annualized loss expectancy. Selecting BIA here would shift the focus away from the financial quantification of a data breach and toward continuity planning, which is a different but related activity.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.