Courseiva

200-201 Security Policies and Procedures Practice Question

An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?

⚠ Common exam trap

Cisco often tests the distinction between quantitative and qualitative risk assessment by describing a scenario with monetary values (quantitative) versus subjective ratings (qualitative), leading candidates to confuse risk treatment or identification with the assessment method itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Quantitative risk assessment

Assigning a monetary value to potential losses is a hallmark of quantitative risk assessment. This method uses numerical data (e.g., dollar amounts, percentages) to calculate metrics such as Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE), enabling objective comparison of risks. In contrast, qualitative methods rely on subjective ratings like high/medium/low.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk treatment

    Why it's wrong here

    Risk treatment covers the response chosen after assessment, such as mitigating, transferring or accepting a risk, not the monetary valuation method itself. It is tempting because treatment follows assessment in the risk lifecycle, but assigning monetary values to potential losses describes quantitative assessment.

  • ✗

    Qualitative risk assessment

    Why it's wrong here

    Qualitative assessment ranks risks using descriptive scales such as high, medium or low, so it cannot assign the monetary loss values the scenario requires. It is tempting because it is faster and needs no financial data, and it would be correct when prioritising risks subjectively rather than performing a quantitative, financially based analysis.

  • ✗

    Risk identification

    Why it's wrong here

    Risk identification only enumerates threats, vulnerabilities and assets; it never attaches monetary values, so it cannot produce the loss figures the scenario describes. It is tempting because identification is the first assessment step, and it would be correct when the goal is compiling a risk register rather than quantifying potential financial loss.

  • ✓

    Quantitative risk assessment

    Why this is correct

    Quantitative risk assessment expresses risk in monetary terms, calculating potential loss values from asset value, exposure factor and annualised rate of occurrence. Assigning a monetary value to potential losses is precisely this method's defining characteristic.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.