Courseiva

CISM Information Security Risk Management Practice Question

Which THREE of the following are typical steps in a qualitative risk assessment?

⚠ Common exam trap

Many candidates confuse qualitative and quantitative risk assessment steps, mistakenly selecting ALE or monetary assignment as part of qualitative analysis because they recall 'risk calculation' without distinguishing the method.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Estimate likelihood and impact using rating scales

Option C is correct because identifying assets and threats is the foundational step of any risk assessment, including qualitative ones, since you must know what you are protecting and what could harm it before evaluating risk. Option A is correct because qualitative risk assessment characteristically uses subjective rating scales (such as High/Medium/Low or 1–5) to estimate likelihood and impact rather than numeric monetary values. Option B is correct because once risks are rated on those scales, the results are used to prioritize risks so that the highest-rated risks receive attention first. Option D is not correct because calculating annualized loss expectancy (ALE = SLE × ARO) is a quantitative technique requiring monetary figures. Option E is not correct because assigning monetary values to impact is also a quantitative step, whereas qualitative assessment relies on descriptive or ordinal ratings.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Estimate likelihood and impact using rating scales

    Why this is correct

    Qualitative risk assessment ranks threats using ordinal rating scales — such as low, medium or high — rather than monetary values. Estimating likelihood and impact this way satisfies the stem's requirement for a typical qualitative step, since it relies on expert judgement and descriptive rankings instead of the quantitative annualised loss figures used in quantitative analysis.

  • ✓

    Prioritize risks based on risk ratings

    Why this is correct

    Prioritising risks by rating is fundamental to qualitative assessment, which ranks threats using ordinal scales rather than monetary values. This satisfies the stem's requirement for a typical step by converting assessed likelihood and impact into relative rankings, enabling analysts to focus remediation on the highest-rated risks without quantitative financial modelling.

  • ✓

    Identify assets and threats

    Why this is correct

    Identifying assets and threats underpins qualitative risk assessment by establishing what requires protection and which adverse events could affect it. This scoping step satisfies the stem's requirement for a typical qualitative step, since subsequent likelihood and impact judgements depend entirely on knowing the assets in scope and the threats relevant to them.

  • ✗

    Calculate annualized loss expectancy (ALE)

    Why it's wrong here

    ALE is a quantitative metric, multiplying single loss expectancy by annualised rate of occurrence; qualitative assessment instead uses ordinal scales such as high, medium and low. It tempts because ALE genuinely belongs in quantitative risk analysis, where monetary loss data and asset values support cost-benefit comparisons of controls.

  • ✗

    Assign monetary values to impact

    Why it's wrong here

    Assigning monetary values is quantitative by definition, since qualitative assessment ranks likelihood and impact on descriptive scales without financial figures. It tempts because monetary impact valuation is central to quantitative analysis, where it feeds ALE calculations and supports return-on-security-investment decisions.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.