Courseiva
mediumMultiple Choice

SSCP Practice Question: A security team is conducting a qualitative risk…

A security team is conducting a qualitative risk assessment for a new cloud application. They want to prioritize risks based on likelihood and impact. Which method should they use to combine these factors?

⚠ Common exam trap

Candidates often confuse qualitative risk assessment with quantitative methods like ALE, assuming any combination of likelihood and impact requires numerical calculation, but the question explicitly states 'qualitative', which directly points to a risk matrix.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk matrix (heat map)

A risk matrix (heat map) is the correct method because it combines qualitative assessments of likelihood and impact into a single visual grid, allowing the team to prioritize risks by their position in the matrix. This approach is standard for qualitative risk assessments where numerical data is unavailable, as it maps ordinal ratings (e.g., low, medium, high) to a color-coded priority level.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk matrix (heat map)

    Why this is correct

    A risk matrix plots likelihood against impact on a grid, producing a heat map that ranks risks into qualitative bands for prioritisation. It combines both factors without requiring monetary values, which suits the qualitative cloud assessment. Other methods, such as SLE calculations, demand quantitative data the team lacks.

  • ✗

    SWOT analysis

    Why it's wrong here

    SWOT analysis evaluates internal strengths and weaknesses against external opportunities and threats for strategic planning; it produces no likelihood-impact pairing for ranking individual risks. It is tempting because it examines threats, and it would be correct when assessing an organisation's overall strategic position rather than prioritising specific cloud application risks.

  • ✗

    Annualized loss expectancy (ALE)

    Why it's wrong here

    ALE multiplies single loss expectancy by annualised rate of occurrence, producing a monetary figure from quantitative inputs; the scenario asks for qualitative likelihood-and-impact prioritisation, not financial estimation. It is tempting because ALE does combine frequency and loss, and it would be correct when sufficient historical data exists to justify cost-benefit decisions numerically.

  • ✗

    Business Impact Analysis (BIA)

    Why it's wrong here

    A BIA quantifies the operational and financial consequences of disrupting business processes, producing recovery priorities and RTO/RPO targets; it does not combine likelihood with impact to rank risks. It is tempting because both inform risk decisions, and a BIA would be correct when determining which systems must be restored first after an outage.

About these practice questions

One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.