mediumMultiple ChoiceObjective-mapped
CISSP Practice Question: Conducting a risk assessment and needs to…
A company is conducting a risk assessment and needs to prioritize risks based on both likelihood and impact. The risk management team decides to use a quantitative approach. Which of the following is a key advantage of using quantitative risk analysis over qualitative risk analysis?
⚠ Common exam trap
Candidates often confuse the ease of communication (qualitative) with the numerical rigor (quantitative), or mistakenly think quantitative analysis is faster because it uses numbers, when in fact it demands more data and time.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
It provides monetary values for risks, facilitating cost-benefit analysis.
Quantitative risk analysis assigns monetary values to assets, threats, and vulnerabilities, enabling precise cost-benefit calculations for risk mitigation options. This allows organizations to compare the cost of controls directly against the expected loss, a key advantage over qualitative methods that rely on subjective rankings.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
It provides monetary values for risks, facilitating cost-benefit analysis.
Why this is correct
Quantitative risk analysis directly translates potential risks into financial terms, such as Annualized Loss Expectancy (ALE), by calculating the monetary impact of a single loss event (SLE) and its annual frequency (ARO). This financial quantification is crucial because it allows organizations to perform a rigorous cost-benefit analysis, comparing the projected monetary losses from a risk against the investment required for mitigation controls. Consequently, it facilitates informed decision-making, ensuring that security expenditures are justified and prioritized based on their financial return on investment.
- ✗
It relies on expert opinions and does not require historical data.
Why it's wrong here
Quantitative risk analysis, contrary to this statement, heavily relies on objective, empirical data rather than solely subjective expert opinions. While expert input can inform initial assumptions or data gaps, the core of quantitative analysis involves using historical loss data, asset valuations, threat frequencies, and vulnerability statistics to calculate precise probabilities and financial impacts. Without verifiable historical data and statistical models, the resulting monetary values would lack the necessary accuracy and credibility for robust financial decision-making.
- ✗
It is easier to communicate to non-technical stakeholders.
Why it's wrong here
Quantitative risk analysis, with its reliance on numerical data and monetary values, is generally more challenging to articulate to non-technical stakeholders than the descriptive scales used in qualitative analysis. While qualitative risk assessments often employ matrices with terms like "high," "medium," and "low" impact and likelihood, making them accessible for broad understanding, quantitative methods require explaining concepts like Annualised Loss Expectancy (ALE) and Return on Investment (ROI) for proposed controls. This option would be tempting if the question focused on the ease of communication for qualitative methods, which excel at providing a high-level overview without requiring deep technical comprehension.
- ✗
It requires less data and is faster to perform.
Why it's wrong here
Quantitative risk analysis is inherently data-intensive and, consequently, more time-consuming and resource-demanding to perform than qualitative methods. It necessitates the meticulous collection and validation of precise numerical data points, including asset values, threat frequencies, control effectiveness, and historical loss events. This extensive data gathering, coupled with complex statistical modeling and calculations required to derive metrics like Annualized Loss Expectancy, makes it a significantly slower and more resource-intensive process.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Risk mitigation
Risk mitigation is the process of reducing the likelihood or impact of a potential security threat to an acceptable level through specific controls and actions.
Key term
Quantitative risk analysis
Quantitative risk analysis is a structured process that uses numerical data and statistical methods to calculate the potential financial impact of risks on an organization's assets and projects.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.