CCSP Security Threats & Risk Management 2 — Questions and Answers
Question 1: Which type of insider threat poses the greatest risk to cargo screening operations because they have legitimate access and knowledge of security procedures?
- External contractor with temporary badge
- Disgruntled employee with system credentials (Correct answer)
- Vendor making routine deliveries
- Visitor escorted through secure areas
Correct answer: Disgruntled employee with system credentials
A disgruntled employee with system credentials combines authorized access, operational knowledge, and malicious intent — the most dangerous insider threat combination.
Question 2: In risk management, what does the term 'residual risk' refer to?
- Risk eliminated after implementing controls
- Risk that remains after all countermeasures are applied (Correct answer)
- Risk transferred to an insurance provider
- Risk identified but not yet assessed
Correct answer: Risk that remains after all countermeasures are applied
Residual risk is the remaining level of risk after security controls and countermeasures have been implemented.
Question 3: A shipper knowingly provides false cargo manifests to avoid screening. This scenario best represents which threat category?
- Unintentional threat
- Deliberate deception / insider facilitation (Correct answer)
- Natural hazard
- Random equipment failure
Correct answer: Deliberate deception / insider facilitation
Providing false manifests is a deliberate act of deception that facilitates smuggling prohibited items past screening checkpoints.
Question 4: Which analytical method ranks threats by multiplying the likelihood of occurrence by the potential impact?
- Fault Tree Analysis
- Risk matrix scoring (Correct answer)
- Delphi technique
- SWOT analysis
Correct answer: Risk matrix scoring
A risk matrix scores threats by multiplying probability (likelihood) by consequence (impact) to produce a prioritized risk ranking.
Question 5: Under the CCSP framework, what is the primary purpose of a vulnerability assessment?
- To determine insurance premiums for cargo losses
- To identify weaknesses in security systems that adversaries could exploit (Correct answer)
- To schedule routine maintenance for X-ray equipment
- To evaluate employee performance during inspections
Correct answer: To identify weaknesses in security systems that adversaries could exploit
A vulnerability assessment systematically identifies gaps and weaknesses in security posture that could be exploited by a threat actor.
Question 6: An air cargo facility receives a tip that a specific shipment may contain an IED. Which immediate action is MOST appropriate?
- Complete screening of the shipment and document results
- Isolate the shipment, notify law enforcement, and follow the facility's emergency response plan (Correct answer)
- Contact the shipper to verify contents before taking action
- Continue normal operations while management decides how to respond
Correct answer: Isolate the shipment, notify law enforcement, and follow the facility's emergency response plan
Suspected IED threats require immediate isolation of the item, law enforcement notification, and activation of the emergency response plan to protect personnel and the facility.
Question 7: What is the key distinction between a threat and a hazard in the CCSP security context?
- A threat is always natural; a hazard is always man-made
- A threat involves intentional hostile action; a hazard may be unintentional or accidental (Correct answer)
- A hazard requires immediate response; a threat can be deferred
- There is no distinction — the terms are interchangeable
Correct answer: A threat involves intentional hostile action; a hazard may be unintentional or accidental
In security contexts, a threat implies intent to cause harm, while a hazard is a condition that may cause harm without necessarily involving deliberate action.
Which type of insider threat poses the greatest risk to cargo screening operations because they have legitimate access and knowledge of security procedures?