ISC2 Certified Cloud Security Professional (CCSP) Practice Question
A retail company plans to host its public web portal in a single IaaS region and is performing a quantitative risk assessment. The portal itself is valued at USD 500,000, and the security team estimates that a successful volumetric DDoS attack would render 40 percent of that value unrecoverable because of lost sales and recovery costs. Industry data for similar tenants show two successful DDoS incidents every five years. What is the annualized loss expectancy (ALE) for this risk and the most appropriate interpretation when deciding whether to fund cloud-based DDoS mitigation?
Approximately USD 500,000; the risk is catastrophic and requires immediate multi-region redundancy.
Approximately USD 200,000; the risk should be transferred entirely through cyber-insurance.
Approximately USD 80,000; the risk is significant enough to justify investing in DDoS mitigation controls.
Approximately USD 40,000; the risk is low enough to accept without new controls.
First calculate the single-loss expectancy (SLE) using the formula SLE = Asset Value × Exposure Factor.
SLE = USD 500,000 × 0.40 = USD 200,000
Next, compute the annualized rate of occurrence (ARO): 2 incidents ÷ 5 years = 0.4 incidents per year.
Finally, determine the annualized loss expectancy (ALE): ALE = SLE × ARO = USD 200,000 × 0.4 ≈ USD 80,000 per year.
An expected annual loss on the order of USD 80,000 is material for most mid-size enterprises and typically warrants investment in preventive or detective security controls such as a cloud-based DDoS mitigation service. The other options either miscalculate the ALE or draw an unjustified risk-treatment conclusion.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is Single-Loss Expectancy (SLE)?
Open an interactive chat with Bash
What is Annualized Rate of Occurrence (ARO)?
Open an interactive chat with Bash
How is Annualized Loss Expectancy (ALE) calculated?
Open an interactive chat with Bash
ISC2 Certified Cloud Security Professional (CCSP)
Cloud Platform & Infrastructure Security
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99
$19.99/mo
Billed monthly, Cancel any time.
3 Month Pass
$44.99
$14.99/mo
One time purchase of $44.99, Does not auto-renew.
MOST POPULAR
Annual Pass
$119.99
$9.99/mo
One time purchase of $119.99, Does not auto-renew.
BEST DEAL
Lifetime Pass
$189.99
One time purchase, Good for life.
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .