SY0-701 Security Program Management and Oversight Practice Question
A business owner asks the security team to compare the cost of two controls for a legacy application in dollar terms. The team estimates the annual chance of a breach, the potential loss per event, and the expected yearly loss after each control is applied. Which risk analysis approach is being used?
⚠ Common exam trap
The SY0-701 exam often tests the distinction between quantitative and qualitative risk analysis by embedding monetary terms in the scenario, leading candidates to mistakenly choose qualitative analysis when they see subjective-sounding phrases like 'annual chance' without recognizing that dollar values are the key indicator of a quantitative approach.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Quantitative risk analysis
The question describes a risk analysis that uses dollar values for the annual chance of a breach, potential loss per event, and expected yearly loss after controls are applied. This is the hallmark of quantitative risk analysis, which assigns monetary or numerical values to risk components (e.g., ALE = SLE × ARO) to compare control costs in objective financial terms. The scenario explicitly asks for a cost comparison in dollar terms, which only a quantitative approach can provide.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Qualitative risk analysis
Why it's wrong here
Qualitative risk analysis does not produce dollar-based values; it assigns subjective ratings such as low, medium, or high to likelihood and impact, often using a risk matrix. Because the results are categorical rather than numerical, they cannot be used to calculate the financial cost of a control or compare it against expected loss in monetary terms. It is useful for prioritization and quick triage, but it does not support a cost-based comparison.
- ✓
Quantitative risk analysis
Why this is correct
Quantitative risk analysis assigns numeric values to risk components, enabling direct cost comparison. It calculates metrics such as asset value, exposure factor, single loss expectancy (SLE), annualized rate of occurrence (ARO), and annualized loss expectancy (ALE). With these figures, an organization can compare the ALE before and after implementing a control, subtract the control's annual cost, and determine if the safeguard provides a positive return on investment. This makes it the correct method for comparing the cost of security measures.
- ✗
Business impact analysis
Why it's wrong here
A business impact analysis (BIA) is a process used for business continuity planning; it identifies critical business functions, dependencies, and recovery requirements such as recovery time objectives (RTOs) and recovery point objectives (RPOs). While it may quantify the impact of a disruption, it does not calculate the cost-effectiveness of specific security controls or compare alternative safeguard investments. The BIA informs recovery strategies, not the financial comparison of risk mitigation options.
- ✗
Risk acceptance
Why it's wrong here
Risk acceptance is one of the risk response strategies, alongside mitigation, transfer, and avoidance, where management explicitly acknowledges the risk and decides to tolerate it without implementing additional controls. It is a decision made after risk analysis has been performed, not an analytical method for estimating expected losses. Accepting risk involves documenting the rationale and potential impact, but it does not involve calculating control costs or comparing alternatives financially.
Go deeper
Related to this question
Learn chapter
Risk Management Concepts
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Quantitative risk analysis
Quantitative risk analysis is a structured process that uses numerical data and statistical methods to calculate the potential financial impact of risks on an organization's assets and projects.
About these practice questions
This SY0-701 question is part of Courseiva's 1,013-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SY0-701 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SY0-701 exam.