SSCP Risk Identification, Monitoring, and Analysis Practice Question
An analyst reviewing the risk register notices that a web application vulnerability has an annualized loss expectancy (ALE) of $40,000 before controls. A web application firewall (WAF) would cost $12,000 per year to operate and is expected to reduce the ALE to $10,000. Based on this quantitative analysis, what should the analyst recommend?
⚠ Common exam trap
The trap here is fixating on the residual annualized loss expectancy instead of comparing the control's cost against the loss it actually prevents.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Recommend the WAF because the control cost of $12,000 is less than the $30,000 reduction in annualized loss expectancy.
Quantitative risk analysis compares the annual cost of a control with the reduction in annualized loss expectancy it produces. The WAF cuts expected loss by $30,000 while costing $12,000 per year, yielding a positive net benefit of $18,000. That favorable relationship is the basis for recommending implementation; the residual loss simply reflects that no control eliminates risk entirely.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Recommend the WAF because the control cost of $12,000 is less than the $30,000 reduction in annualized loss expectancy.
Why this is correct
The control yields a $30,000 annual reduction in expected loss and costs $12,000 to operate, producing a net benefit of $18,000 per year. Since the cost is clearly below the mitigated loss, the quantitative analysis supports implementing the WAF as a cost-effective risk mitigation measure.
- ✗
Recommend against the WAF because the annualized loss expectancy is still $10,000 after implementation.
Why it's wrong here
A residual ALE of $10,000 does not by itself disqualify a control. The decision hinges on whether the control's cost is less than the loss it prevents. Since the WAF reduces expected annual loss by $30,000 while costing $12,000, the remaining exposure is acceptable relative to the savings produced.
- ✗
Recommend against the WAF because the $12,000 cost exceeds ten percent of the original $40,000 annualized loss expectancy.
Why it's wrong here
There is no standard rule that control cost must stay under ten percent of ALE. That heuristic is not part of quantitative risk analysis. The valid comparison is between the control's annual cost and the reduction in expected loss, which here favors implementation rather than rejection.
- ✗
Recommend the WAF only if the residual annualized loss expectancy can be reduced to zero.
Why it's wrong here
No realistic control drives expected loss to zero, and requiring that outcome would effectively forbid all mitigation. Quantitative analysis seeks cost-effective reduction, not elimination. The WAF already lowers expected loss from $40,000 to $10,000 at a cost well below the savings, so this condition is unnecessarily strict.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.