NIST CSF Practice Question: What is a quantitative risk assessment? | CyberCertPrep
NISTNIST CSFProfiles RiskEASYFree question
What is a quantitative risk assessment?
A.A risk assessment that only considers a quantity of vulnerabilities
B.A risk assessment that counts the number of security incidents
C.A risk assessment performed by a specific number of analysts
D.A risk assessment that uses numerical values and financial metrics to measure risk
Why D is correct
A quantitative risk assessment uses numerical values and financial metrics to measure risk, typically calculating expected monetary losses using formulas like Annual Loss Expectancy (ALE).
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Profiles Risk
CSF Profiles and risk: building organizational profiles, prioritizing outcomes, and managing cybersecurity risk.
This question belongs to the "Identify" domain, which makes up about 20% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What is the difference between a Current Profile and a Target Profile?