hardMultiple SelectObjective-mapped
CISSP Practice Question: Which TWO of the following are essential…
Which TWO of the following are essential components of a quantitative risk analysis formula? (Choose two.)
⚠ Common exam trap
It's easy for candidates to confuse Exposure Factor (EF) as a direct component of the final formula, when in fact it is an intermediate input to SLE, not a standalone variable in the ALE equation; similarly, Residual Risk is a post-control metric, not a formula component, and Control Frequency is a fabricated term not found in any standard risk analysis framework.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Annual Rate of Occurrence (ARO)
In quantitative risk analysis, the formula for calculating Annualized Loss Expectancy (ALE) is ALE = SLE × ARO. The Single Loss Expectancy (SLE) represents the monetary loss expected from a single occurrence of a risk, calculated as Asset Value × Exposure Factor (EF). The Annual Rate of Occurrence (ARO) is the expected frequency of that risk occurring per year. Both SLE and ARO are direct, essential multipliers in the core ALE formula, making them fundamental components of the quantitative risk analysis equation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Annual Rate of Occurrence (ARO)
Why this is correct
Annual Rate of Occurrence (ARO) quantifies the expected number of times a specific risk event is projected to occur within a single year. It is a critical input for calculating the Annual Loss Expectancy (ALE), where ALE = SLE × ARO. Without an estimated frequency, the annual financial impact of a risk cannot be accurately projected, making it an indispensable element for quantitative risk assessment.
- ✗
Exposure Factor (EF)
Why it's wrong here
The Exposure Factor (EF) represents the percentage of an asset's value that is likely to be lost if a specific risk event occurs. While EF is crucial for calculating the Single Loss Expectancy (SLE) (SLE = Asset Value × EF), it is an intermediate variable, not a direct, standalone component of the final Annual Loss Expectancy (ALE) formula. Therefore, it is not considered one of the two essential direct components of the overall quantitative risk analysis output.
- ✗
Residual Risk
Why it's wrong here
Residual risk refers to the level of risk that remains after security controls, countermeasures, or other risk mitigation strategies have been implemented. While managing residual risk is a vital part of the overall risk management process, it is an outcome or result of risk treatment, not an input or fundamental component used in the initial calculation of quantitative risk metrics like Single Loss Expectancy (SLE) or Annual Loss Expectancy (ALE). Its assessment follows the primary quantitative analysis.
- ✓
Single Loss Expectancy (SLE)
Why this is correct
Single Loss Expectancy (SLE) quantifies the monetary loss expected from a single occurrence of a specific risk event. It is calculated by multiplying the asset's value by the Exposure Factor (SLE = Asset Value × EF). As a fundamental building block for determining the Annual Loss Expectancy (ALE), SLE provides the crucial financial impact per incident, making it an indispensable component for any quantitative risk assessment.
- ✗
Control Frequency (CF)
Why it's wrong here
"Control Frequency" is not a recognized or standard metric within the established methodologies of quantitative risk analysis, such as those used to calculate Single Loss Expectancy (SLE) or Annual Loss Expectancy (ALE). While the effectiveness and operational frequency of controls certainly influence the Annual Rate of Occurrence (ARO), "Control Frequency" itself is not a direct, quantifiable component in the standard formulas for assessing financial risk impact. It's an operational detail rather than a core risk calculation element.
Go deeper
Related to this question
Learn chapter
Asset Security: Classification and Handling
Key term
Asset
In IT and cybersecurity, an asset is anything valuable that an organization owns or controls, including data, hardware, software, people, and intellectual property.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
This CISSP question is part of Courseiva's 747-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.