TechKnowSurge
CompTIA Security+ 5.2 ISC2 CISSP 1.9 CompTIA SecurityX 1.3 NIST CSF GV.RM-06 NIST CSF ID.RA-04 NIST NICE K0835 NIST CSF ID.RA-05
InteractiveSecurityFree

Risk Calculation Activity

Run the quantitative risk chain on real scenario numbers — SLE from asset value and exposure factor, ALE from SLE and rate of occurrence, and any missing term solved back out.

Complete this interactive to capture a CTF flag worth 5 points.

About this interactive

Quantitative risk is two multiplications: SLE = AV × EF, then ALE = SLE × ARO. This drill makes you run them on the kind of numbers a risk register actually carries. Scenario items hand over a situation — a datacenter fire on a $2,000,000 facility at a 40% exposure factor, fifteen stolen laptops a year, ransomware taking 60% of a customer database, a flood spoiling 8% of warehouse stock — and take the single loss or the annual figure. Other items run the formulas backwards, solving for the asset value, the exposure factor or the rate of occurrence from what a register line already shows, because the exam and the job both ask for the missing term as often as they ask for the answer. Two items name the value rather than compute it, and one ranks two unlike risks: a $500,000 single loss at an ARO of 0.02 against an $8,000 loss three times a year, where the larger single loss is the cheaper risk. Every answer is typed and graded exactly, and a miss shows the derivation — including the two errors that produce most wrong answers here, entering an exposure factor as 8 or 0.8 instead of 0.08, and entering an ARO as the interval in years rather than as events per year.

What you'll learn

Aligned to

CompTIA Security+
5.2 Explain elements of the risk management process.
ISC2 CISSP
1.9 Understand and apply risk management concepts
CompTIA SecurityX
1.3 Explain the importance of risk management for an enterprise.
NIST CSF
GV.RM-06 A standardized method for calculating, documenting, categorizing, and prioritizing cybersecurity risks is established and communicated.
ID.RA-04 Potential impacts and likelihoods of threats exploiting vulnerabilities are identified and recorded.
ID.RA-05 Threats, vulnerabilities, likelihoods, and impacts are used to understand inherent risk and inform risk response prioritization.
NIST NICE
K0835 Knowledge of risk assessment principles and practices

Key terms

Quantitative Risk Analysis
A risk analysis method that assigns numerical values — such as probability percentages and monetary loss estimates — to risks in order to prioritize them and justify the cost of controls. It produces metrics like Single Loss Expectancy and Annualized Loss Expectancy.
Asset Value
AV
The monetary worth assigned to an asset, which may decrease over time through depreciation.
Exposure Factor
EF
The percentage of an asset's value estimated to be lost if a specific risk event occurs.
Single Loss Expectancy
SLE
Single Loss Expectancy is the expected monetary loss from a single occurrence of a risk event, calculated by multiplying the asset value by the exposure factor for that threat.
Annualized Rate of Occurrence
ARO
Annualized Rate of Occurrence is an estimate of how frequently a specific threat event is expected to occur within a given year, used in quantitative risk calculations.
Annualized Loss Expectancy
ALE
Annualized Loss Expectancy is a risk metric representing the expected yearly monetary loss from a threat, calculated by multiplying the Single Loss Expectancy by the Annualized Rate of Occurrence.
Risk Prioritization
The process of ranking identified risks by their potential impact and likelihood to determine which require the most urgent attention.

Topics

Interactive Calculation Risk Risk Management Quantitative Risk Analysis Sle Ale Aro

About TechKnowSurge

TechKnowSurge builds IT and cybersecurity professionals through hands-on, concept-first training built around real understanding — not memorization. Free interactive tools, structured programs, and 25+ years of real-world experience, all in one place.

Explore free tools and programs →