
EC-CouncilCloud Security Essentials
Domain 7Objective 4
Quantitative vs. Qualitative Risk Assessment CSE Practice Questions (Page 8)
Part of the Cloud Security Risk Assessment and Management domain, which makes up ~13% of our current practice bank.
43questions here
9free pages
11concepts
Questions 36–40
- 36
Which of the following is a key characteristic of quantitative risk assessment?
Select an answer first - 37
A company is evaluating the risk of a ransomware attack on its file servers. The servers are valued at $200,000, and an attack would likely destroy 50% of the data's value. The estimated frequency of such an attack is once every 4 years. What is the Single Loss Expectancy (SLE)?
Select an answer first - 38
A company is assessing the risk of a denial-of-service (DoS) attack on its public-facing web application. The application generates $1,000,000 in annual revenue, and a successful attack would cause a 10% loss of revenue for the year. The estimated frequency of such an attack is once every 2 years. What is the Annualized Loss Expectancy (ALE)?
Select an answer first - 39
A security team is using a qualitative risk assessment to evaluate threats to a cloud-based CRM. They have identified a list of potential risks and need to prioritize them. Which technique would be most effective for this purpose?
Select an answer first - 40
A small business with a limited security budget is performing its first cloud risk assessment. The team has no historical loss data and limited expertise. They need a quick, low-cost method to identify and prioritize risks. They decide to use a qualitative approach. What is the primary disadvantage they should be aware of?
Select an answer first
Finished these 5 questions?
Review the revealed explanations, or continue through the curriculum.
Free Basic Practice is a study aid with revealable answers — not a scored exam. Examers.io is independent and not affiliated with or endorsed by EC-Council. “CSE” is a trademark of its owner, used for identification only.