Courseiva
easyMultiple Choice

CCSP Practice Question: Which risk assessment method uses subjective…

Which risk assessment method uses subjective scales to assign probabilities and impacts?

⚠ Common exam trap

ISC2 often tests the distinction between qualitative and semi-quantitative methods, where candidates confuse subjective scales (qualitative) with ordinal numerical scales (semi-quantitative), leading them to incorrectly select semi-quantitative risk assessment.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Qualitative risk assessment

Qualitative risk assessment (option C) is correct because it relies on subjective scales (e.g., high, medium, low) to assign probabilities and impacts, rather than numerical data. This method is commonly used in cloud security to quickly evaluate risks when precise data is unavailable, aligning with the CCSP domain of Legal, Risk and Compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Semi-quantitative risk assessment

    Why it's wrong here

    Semi-quantitative methods map qualitative judgements onto numeric scales, but the stem specifies subjective scales assigning probabilities and impacts, which is qualitative assessment. It is tempting because semi-quantitative outputs look measurable, yet it converts subjective ratings into numbers rather than leaving them as the subjective scales described.

  • ✗

    Quantitative risk assessment

    Why it's wrong here

    Quantitative assessment assigns monetary values and statistically derived probabilities from historical data, not subjective scales. It is tempting because numeric output appears rigorous, but the stem describes qualitative judgement-based ratings; quantitative methods require empirical frequency data that subjective probability scales do not provide.

  • ✓

    Qualitative risk assessment

    Why this is correct

    Qualitative risk assessment ranks likelihood and impact using descriptive or ordinal scales, such as low, medium and high, rather than monetary values or annualised loss figures. That subjective scoring is precisely the mechanism the stem describes.

  • ✗

    Bottom-up risk assessment

    Why it's wrong here

    Bottom-up assessment describes who performs the analysis, at asset or process level, not the measurement scale used. It is tempting because grassroots input sounds subjective, yet the stem asks about the rating method; bottom-up can be qualitative, semi-quantitative or quantitative, so it does not define the subjective scales.

About these practice questions

One of 934 original CCSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CCSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CCSP exam.