Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A company is conducting a risk assessment for its new payment processing system. They identify a potential threat where an attacker could exploit a zero-day vulnerability in the system's web interface to steal customer credit card data. The team estimates the likelihood of this occurring as 'Medium' and the impact as 'High'. What is the risk rating for this scenario using a simple qualitative risk matrix?

  1. ALow
  2. BHigh
  3. CCritical
  4. DMedium
Show answer & explanation

Correct answer: B. High

In a typical qualitative risk matrix, a 'Medium' likelihood combined with a 'High' impact would result in a 'High' risk rating. This indicates a significant concern that requires attention.

Why the other options are wrong

  • A. Low risk typically results from low likelihood and low impact.
  • C. Critical risk is typically reserved for 'High' likelihood and 'Critical' impact.
  • D. Medium risk could be a combination like medium likelihood/medium impact or low likelihood/high impact.

Qualitative Risk Rating

A method of assessing risk by assigning descriptive values (e.g., Low, Medium, High) to the likelihood and impact of a risk, often using a matrix.

  • Uses descriptive categories instead of numeric values.
  • Subjective but useful for initial prioritization.
  • Often represented in a grid or matrix.

Memory trick: Qualitative matrix: Like a weather forecast, not exact numbers.

More Risk Management questions