200-201 Security Policies and Procedures Practice Question
An organization is conducting a risk assessment and assigns a monetary value to potential losses. Which risk assessment method is being used?
⚠ Common exam trap
Cisco often tests the distinction between quantitative and qualitative risk assessment by describing a scenario with monetary values (quantitative) versus subjective ratings (qualitative), leading candidates to confuse risk treatment or identification with the assessment method itself.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quantitative risk assessment
Assigning a monetary value to potential losses is a hallmark of quantitative risk assessment. This method uses numerical data (e.g., dollar amounts, percentages) to calculate metrics such as Single Loss Expectancy (SLE) and Annualized Loss Expectancy (ALE), enabling objective comparison of risks. In contrast, qualitative methods rely on subjective ratings like high/medium/low.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Risk treatment
Why it's wrong here
Risk treatment covers the response chosen after assessment, such as mitigating, transferring or accepting a risk, not the monetary valuation method itself. It is tempting because treatment follows assessment in the risk lifecycle, but assigning monetary values to potential losses describes quantitative assessment.
- ✗
Qualitative risk assessment
Why it's wrong here
Qualitative assessment ranks risks using descriptive scales such as high, medium or low, so it cannot assign the monetary loss values the scenario requires. It is tempting because it is faster and needs no financial data, and it would be correct when prioritising risks subjectively rather than performing a quantitative, financially based analysis.
- ✗
Risk identification
Why it's wrong here
Risk identification only enumerates threats, vulnerabilities and assets; it never attaches monetary values, so it cannot produce the loss figures the scenario describes. It is tempting because identification is the first assessment step, and it would be correct when the goal is compiling a risk register rather than quantifying potential financial loss.
- ✓
Quantitative risk assessment
Why this is correct
Quantitative risk assessment expresses risk in monetary terms, calculating potential loss values from asset value, exposure factor and annualised rate of occurrence. Assigning a monetary value to potential losses is precisely this method's defining characteristic.
About these practice questions
One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.