Certified SOC Analyst (CSA) — Question 5
Which of the following formula represents the risk?
Answer options
- A. Risk = Likelihood × Severity × Asset Value
- B. Risk = Likelihood × Consequence × Severity
- C. Risk = Likelihood × Impact × Severity
- D. Risk = Likelihood × Impact × Asset Value
Correct answer: D
Explanation
The correct answer is D because it accurately represents risk as a function of likelihood and the impact of potential loss, combined with asset value. Option A incorrectly includes Severity, while B introduces Consequence, which is not standard in risk calculation. Option C also fails by omitting Asset Value, which is crucial for understanding the overall risk.