SSCP Risk Identification, Monitoring, and Analysis Practice Question
During a qualitative risk analysis, an organization assesses a threat of a data breach due to weak encryption. The likelihood is rated as 'Medium' and the impact as 'High'. According to a standard 3x3 risk matrix, what is the overall risk rating?
⚠ Common exam trap
SSCP often tests the mechanical application of a risk matrix, and candidates err by assuming Medium likelihood always yields Medium risk regardless of impact, or by inventing a 'Critical' rating that does not exist in a 3x3 matrix.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
High
In a standard 3x3 qualitative risk matrix, likelihood and impact are each rated Low, Medium, or High, and the intersection of Medium likelihood with High impact yields a High overall risk rating. This is the conventional mapping used in most risk frameworks. The combination is serious enough to warrant prioritized treatment but does not reach the highest tier.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Medium
Why it's wrong here
A 3x3 matrix maps Medium likelihood against High impact to High, not Medium. Medium arises from combinations such as Medium likelihood with Medium impact, or Low likelihood with High impact. Weak encryption exposing a data breach carries greater exposure than the matrix's middle band.
- ✓
High
Why this is correct
A standard 3x3 matrix maps Medium likelihood against High impact to High risk, because impact drives severity upward when likelihood is not Low. The combination does not average to Medium; the matrix's defined intersection for these two ratings is High.
- ✗
Low
Why it's wrong here
A 3x3 matrix maps Medium likelihood against High impact to High, not Low. Low would require both axes to sit at the bottom of the scale, such as Low likelihood with Low impact. Selecting Low understates exposure from weak encryption on a high-impact breach.
- ✗
Critical
Why it's wrong here
A 3x3 matrix has only Low, Medium and High bands, so Critical cannot be produced. Critical appears in 4x4 or 5x5 matrices that add extra severity tiers. Here Medium likelihood with High impact resolves to High, the top band available.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.