CRISC Certified in Risk and Information Systems Control – Question303

During which of the following processes, probability and impact matrix are prepared?

A.
Risk response
B. Monitoring and Control Risk
C. Quantitative risk assessment
D. Qualitative risk assessment

Correct Answer: D

Explanation:

Explanation:
The probability and impact matrix is a technique to prioritize identified risks of the project on their risk rating, and are being prepared while performing qualitative risk analysis. Evaluation of each risk’s importance and, hence, priority for attention, is typically conducted using a look-up table or a probability and impact matrix. This matrix specifies combinations of probability and impact that lead to rating the risks as low, moderate, or high priority.
Incorrect Answers: A, B: These processes are part of Risk Management. The probability and impact matrix is prepared during the qualitative risk analysis for further quantitative analysis and response based on their risk rating.
C: SLE, ARO and ALE are used in quantitative risk assessment.