CISSP Security and Risk Management Practice Question
In qualitative risk analysis, a risk is assessed with a likelihood of 4 (on a scale of 1-5) and an impact of 5. The risk matrix defines scores of 15-25 as high. What is the risk rating?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High
Likelihood × Impact = 4 × 5 = 20, which falls in the high range (15-25).
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Low
Why it's wrong here
In qualitative risk analysis, risk is often calculated as the product of likelihood and impact. A score of 20, derived from a typical 4x5 or 5x5 matrix where 4 represents a high likelihood and 5 represents a very high impact, significantly exceeds the thresholds commonly defined for a "Low" risk rating. Low risks are typically associated with scores in the single digits, indicating minimal potential harm or very infrequent occurrence.
- ✗
Medium
Why it's wrong here
A risk score of 20, resulting from a multiplication of likelihood and impact, is generally too substantial to be categorized as "Medium" within a standard qualitative risk matrix. Medium risks usually fall into an intermediate range, often between 6 and 14 on a typical 5x5 scale, representing a moderate potential for adverse effects or occurrence. A score of 20 indicates a much greater concern than what is typically assigned to a medium-level threat.
- ✓
High
Why this is correct
A risk score of 20, calculated as the product of a high likelihood (e.g., 4 on a 5-point scale) and a very high impact (e.g., 5 on a 5-point scale), correctly places the risk in the "High" category. In a qualitative risk matrix, the "High" range typically encompasses scores from approximately 15 to 25, signifying a significant probability of occurrence combined with substantial potential negative consequences that demand immediate attention and mitigation strategies.
- ✗
Critical
Why it's wrong here
While a risk score of 20 represents a substantial threat, it typically does not reach the "Critical" classification in most qualitative risk matrices. "Critical" risks are generally reserved for the absolute highest scores, often 25 (e.g., 5x5), indicating an almost certain occurrence with catastrophic impact. A score of 20, while demanding high priority, usually falls just below the threshold for an existential or immediate system-failure level threat.
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Qualitative risk analysis
Qualitative risk analysis is a subjective, scenario-based approach to prioritizing information security risks by evaluating their likelihood and potential impact using predefined scales rather than numerical calculations.
About these practice questions
Courseiva writes every CISSP question from scratch — 747 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.