โ† All CCP Flashcard Decks

Quantitative Risk Assessment Flashcards

7 cards from real CCP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Quantitative Risk Assessment flashcards as text
  1. When using threat intelligence data in quantitative risk assessment, what is the primary challenge with externally reported breach statistics?

    Answer: Survivorship and reporting biases mean they may not represent the true frequency of incidents

    External breach data suffers from reporting bias (only notable incidents are publicized) and survivorship bias, skewing frequency estimates.

  2. A CISO must present cyber risk to the board using quantitative metrics. Which format best communicates risk in financial terms?

    Answer: Annualized loss expectancy ranges with confidence intervals

    Boards understand financial exposure; ALE ranges with confidence intervals translate cyber risk into business-relevant monetary terms.

  3. In quantitative risk assessment, what is a 'risk appetite threshold' used for?

    Answer: To define the level of risk the organization is willing to accept before requiring treatment

    A risk appetite threshold defines the acceptable level of residual risk; risks exceeding it must be treated, transferred, or escalated.

  4. Which of the following is a key limitation of using historical loss data in quantitative cyber risk models?

    Answer: Past cyber incidents may not predict future losses due to rapidly evolving threat landscapes

    The cyber threat landscape evolves rapidly, meaning historical breach data may poorly predict future risks from new attack vectors.

  5. An organization is deciding between two controls: Control A costs $100K and reduces ALE by $150K; Control B costs $200K and reduces ALE by $250K. Which should be prioritized based purely on ROSI?

    Answer: Control A because it has a higher ROSI (50% vs 25%)

    ROSI for A = ($150K-$100K)/$100K = 50%; ROSI for B = ($250K-$200K)/$200K = 25%; Control A is more efficient per dollar spent.

  6. What is 'loss exceedance probability' (LEP) and how is it used in cyber risk quantification?

    Answer: A curve showing the probability that losses will exceed various threshold amounts

    A loss exceedance curve plots probability on one axis against loss amounts on the other, showing the chance losses surpass any given threshold.

  7. When calibrating expert estimates in a quantitative risk model, what technique helps reduce overconfidence bias in probability judgments?

    Answer: Using calibration training and asking experts for confidence interval ranges rather than point estimates

    Calibration training teaches experts to accurately express uncertainty, and eliciting ranges rather than point estimates reduces overconfidence bias.