Cisco Certified Support Technician (CCST) CybersecurityRisk ManagementMedium

A company is performing a qualitative risk assessment for its new e-commerce platform. They identify a potential Distributed Denial of Service (DDoS) attack as a threat. They rate the likelihood of this attack as 'High' and the impact as 'Severe' based on historical data and expert opinion. What is the next logical step in their risk assessment process after determining these ratings?

  1. ACalculate the Annualized Loss Expectancy (ALE).
  2. BDevelop a detailed incident response plan for a DDoS attack.
  3. CPurchase cyber insurance to cover potential DDoS losses.
  4. DDetermine the overall risk level for the DDoS threat.
Show answer & explanation

Correct answer: D. Determine the overall risk level for the DDoS threat.

After rating the likelihood and impact in a qualitative assessment, the next step is typically to combine these ratings to determine the overall risk level (e.g., Low, Medium, High). This helps prioritize risks before moving to response strategies.

Why the other options are wrong

  • A. ALE calculation is part of quantitative, not qualitative, assessment.
  • B. Developing an incident response plan is a risk mitigation strategy, which comes after determining the risk level and prioritizing.
  • C. Purchasing cyber insurance is a risk transfer strategy, which comes after risk assessment and prioritization.

Qualitative Risk Assessment

A method of assessing risks by using descriptive categories (e.g., High, Medium, Low) for likelihood and impact, rather than numerical values.

  • Relies on expert judgment and experience.
  • Often uses a risk matrix to combine likelihood and impact.
  • Helps prioritize risks for further action.

Memory trick: Identify, Rate, Combine: The qualitative risk loop.

More Risk Management questions