CompTIA SecurityX (CAS-005)Governance, Risk and ComplianceHard

A financial institution is evaluating its enterprise-wide risk management program. The Chief Risk Officer (CRO) wants to move beyond simply identifying risks to understanding the potential financial impact of various cyber events and prioritizing mitigation efforts based on this impact. Which of the following approaches should the CRO implement to achieve this objective?

  1. AQuantitative Risk Assessment
  2. BQualitative Risk Assessment
  3. CCompliance Checklist Review
  4. DRisk Register Maintenance
Show answer & explanation

Correct answer: A. Quantitative Risk Assessment

A quantitative risk assessment focuses on assigning monetary values to assets, threats, and vulnerabilities to calculate the potential financial loss from a cyber event. This allows the CRO to prioritize mitigation based on actual financial impact, moving beyond subjective qualitative ratings.

Why the other options are wrong

  • B. Qualitative risk assessment uses subjective ratings (e.g., high, medium, low) and does not provide specific financial impact figures.
  • C. Compliance checklist review assesses adherence to regulations but does not quantify the financial impact of risks.
  • D. Risk register maintenance is a record-keeping activity for identified risks, not a method for financial impact calculation.

Quantitative Risk Assessment

An objective, data-driven approach to risk assessment that assigns monetary values to assets, threats, vulnerabilities, and the potential losses from security incidents.

  • Uses formulas like ALE = SLE x ARO to calculate financial risk.
  • Provides a clear financial justification for security investments.
  • Requires detailed data on asset values, incident frequency, and recovery costs.

Memory trick: Quantity counts the cash, quality describes the feel.

More Governance, Risk and Compliance questions