CSS CSS Threat Intelligence and Risk Communication 1 — Questions and Answers
Question 1: When communicating security risk to a non-technical client, the most effective approach is to:
- Use technical jargon to establish credibility
- Translate threats into financial, operational, or reputational terms the client already cares about (Correct answer)
- Provide a comprehensive technical threat briefing document
- Rely primarily on crime statistics from national databases
Correct answer: Translate threats into financial, operational, or reputational terms the client already cares about
Non-technical decision-makers respond to risk framed in business terms — loss of revenue, liability exposure, or reputational damage — rather than security-specific language.
Question 2: A CSS is presenting to a retail client about shoplifting trends. Which data source provides the most credible and actionable local threat intelligence?
- Global cybersecurity reports from major vendors
- Local law enforcement crime mapping data combined with the client's own loss prevention incident logs (Correct answer)
- Social media posts from the area
- Industry association membership directories
Correct answer: Local law enforcement crime mapping data combined with the client's own loss prevention incident logs
Combining local law enforcement crime data with the client's own loss history creates a highly specific, credible threat picture directly relevant to their location and operations.
Question 3: Which of the following best describes the 'threat landscape' as used in security sales communications?
- A physical map of the client's property perimeter
- The full range of current and emerging threats relevant to a specific industry, geography, or organization type (Correct answer)
- A list of all security incidents from the past year
- A vendor comparison chart for security products
Correct answer: The full range of current and emerging threats relevant to a specific industry, geography, or organization type
The threat landscape encompasses all relevant threats — criminal, physical, cyber, and operational — specific to the prospect's environment and sector.
Question 4: A CSS is presenting to a healthcare client about recent physical security incidents at hospitals. The primary regulatory framework they should reference is:
- PCI DSS
- HIPAA's physical safeguard requirements (Correct answer)
- NFPA 101 only
- SOX compliance standards
Correct answer: HIPAA's physical safeguard requirements
HIPAA's physical safeguard requirements mandate that healthcare organizations implement controls to protect facilities and equipment housing patient data.
Question 5: When a client questions whether their business is a realistic target for crime, the CSS should:
- Agree with them to avoid appearing alarmist
- Present industry-specific victimization statistics and local incident data relevant to their business type and location (Correct answer)
- Use fear-based tactics to override their objection
- Refer them to law enforcement for an assessment
Correct answer: Present industry-specific victimization statistics and local incident data relevant to their business type and location
Factual, industry-specific incident data provides an objective basis for risk discussion without resorting to fear-based selling tactics that undermine credibility.
Question 6: What is 'vulnerability assessment' in the context of a CSS pre-sales security review?
- A cybersecurity penetration test
- A systematic identification of physical, procedural, and technological weaknesses in a client's current security posture (Correct answer)
- An audit of the client's insurance policy coverage
- A review of the client's employee background check records
Correct answer: A systematic identification of physical, procedural, and technological weaknesses in a client's current security posture
A vulnerability assessment identifies gaps in a client's physical security environment across people, processes, and technology before a solution is proposed.
When communicating security risk to a non-technical client, the most effective approach is to: