Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

IIBA-CCA Exam - Topic 2 Question 13 Discussion

How is a risk score calculated?
B) Based on the combination of probability and impact
A) Based on the confidentiality, integrity, and availability characteristics of the system
C) Based on past experience regarding the risk
D) Based on an assessment of threats by the cyber security team

IIBA-CCA Exam - Topic 2 Question 13 Discussion

Actual exam question for IIBA's IIBA-CCA exam
Question #: 13
Topic #: 2
[All IIBA-CCA Questions]

How is a risk score calculated?

Show Suggested Answer Hide Answer
Suggested Answer: B

A risk score is commonly calculated by combining two core factors: how likely a risk scenario is to occur and how severe the consequences would be if it did occur. This is often described in cybersecurity risk documentation as likelihood times impact, or as a structured mapping using a risk matrix. Probability or likelihood reflects the chance that a threat event will exploit a vulnerability under current conditions. It may consider elements such as threat activity, exposure, ease of exploitation, control strength, and historical incident patterns. Impact reflects the magnitude of harm to the organization, usually measured across business disruption, financial loss, legal or regulatory exposure, reputational damage, and harm to confidentiality, integrity, or availability.

While confidentiality, integrity, and availability are essential for understanding what matters and can influence impact ratings, they are typically inputs into impact determination rather than the full scoring method by themselves. Past experience and expert threat assessment can inform likelihood estimates, but they are not the standard calculation model on their own. The key concept is that risk must reflect both chance and consequence; a highly impactful event with very low likelihood may be scored similarly to a moderate impact event with high likelihood depending on the organization's methodology.

Therefore, the most accurate description of how a risk score is calculated is the combination of probability and impact, enabling prioritization and consistent risk treatment decisions.


Contribute your Thoughts:

0/2000 characters
William
2 days ago
I lean towards B. It’s systematic.
upvoted 0 times
...
Mozell
7 days ago
D is crucial for current threats.
upvoted 0 times
...
Franchesca
12 days ago
I feel like A is a good starting point.
upvoted 0 times
...
Annita
18 days ago
C is too subjective for me.
upvoted 0 times
...
Phillip
23 days ago
D is also important, but B is broader.
upvoted 0 times
...
Leatha
28 days ago
A seems relevant too, but B covers more.
upvoted 0 times
...
Gracie
1 month ago
I agree, B is the best choice. It's logical.
upvoted 0 times
...
Rocco
1 month ago
I think it's B. Probability and impact make sense.
upvoted 0 times
...
Jesusa
1 month ago
Totally agree with B! That's the most logical approach.
upvoted 0 times
...
Val
2 months ago
Wait, are we really calculating it based on confidentiality and integrity? That seems off.
upvoted 0 times
...
Goldie
2 months ago
Definitely a mix of threats assessed by the team too.
upvoted 0 times
...
Mickie
2 months ago
I think it's more about past experiences, honestly.
upvoted 0 times
...
Serina
2 months ago
It's all about probability and impact!
upvoted 0 times
...
Glynda
2 months ago
I practiced a question similar to this, and I think the cyber security team's assessment of threats is crucial, but I don't know if it alone determines the risk score.
upvoted 0 times
...
Tina
2 months ago
I feel like past experience regarding risk could play a role, but it seems more subjective compared to the other options.
upvoted 0 times
...
Precious
3 months ago
I remember something about confidentiality, integrity, and availability being important, but I can't recall if they directly relate to risk scoring.
upvoted 0 times
...
Tess
3 months ago
I think the risk score is calculated based on the combination of probability and impact, but I'm not entirely sure if that's the only factor.
upvoted 0 times
...

Save Cancel