
EC-CouncilCloud Security Essentials
Domain 7Objective 4
Quantitative vs. Qualitative Risk Assessment CSE Practice Questions (Page 7)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
43questions here
9free pages
11concepts
Questions 31–35
- 31
When is it most appropriate to use a qualitative risk assessment?
Select an answer first - 32
Which of the following is a key characteristic of qualitative risk assessment?
Select an answer first - 33
A security consultant is helping a client perform a qualitative risk assessment for a cloud environment. The client's management is concerned that the results may be too subjective and inconsistent across different business units. The consultant wants to improve the reliability of the qualitative assessment without switching to a full quantitative approach. Which strategy is most effective?
Select an answer first - 34
A security analyst is tasked with performing a quantitative risk assessment for a cloud storage service. The analyst has detailed asset inventories and historical incident data. However, the assessment is taking longer than expected because of the need to assign precise monetary values to every asset and calculate SLE and ALE for each threat. What is the primary disadvantage of the quantitative approach being experienced?
Select an answer first - 35
Which statement best describes a qualitative risk assessment?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.