NCIC Risk Management & Mitigation 3 — Questions and Answers
Question 1: When an analyst applies the 'all-hazards' approach to risk management, this means:
- Focusing exclusively on terrorism-related threats
- Addressing only natural disasters in the planning process
- Using a comprehensive framework that accounts for all types of threats, hazards, and incidents (Correct answer)
- Prioritizing cyber threats above physical threats
Correct answer: Using a comprehensive framework that accounts for all types of threats, hazards, and incidents
The all-hazards approach ensures plans and assessments address the full spectrum of threats including terrorism, natural disasters, pandemics, and technological failures.
Question 2: In a fusion center environment, 'deconfliction' primarily serves to mitigate which risk?
- Budget overruns in multi-agency operations
- Accidental interference between concurrent law enforcement investigations (Correct answer)
- Unauthorized media disclosures
- Civil liability from informant use
Correct answer: Accidental interference between concurrent law enforcement investigations
Deconfliction systems prevent agencies from unknowingly operating in the same space, which could compromise investigations or create officer safety hazards.
Question 3: Which risk mitigation technique involves reducing the likelihood that a threat will successfully exploit a vulnerability?
- Consequence reduction
- Deterrence (Correct answer)
- Threat suppression
- Recovery planning
Correct answer: Deterrence
Deterrence reduces the probability of an attack by making potential adversaries believe the costs of action outweigh the benefits.
Question 4: A law enforcement agency discovers a vulnerability in its records management system. The agency decides to accept this risk without mitigation. This is appropriate ONLY when:
- The vulnerability is publicly known
- The cost of mitigation exceeds the potential impact and probability warrants acceptance (Correct answer)
- Leadership is unaware of the vulnerability
- No funding is available regardless of risk level
Correct answer: The cost of mitigation exceeds the potential impact and probability warrants acceptance
Risk acceptance is a valid strategy only when the cost-benefit analysis shows that the expense or difficulty of mitigation is not justified by the threat level and potential impact.
Question 5: The concept of 'defense in depth' applied to criminal intelligence operations means:
- Deploying the most resources to the highest-risk areas only
- Using multiple overlapping layers of security controls so a single failure does not compromise the whole system (Correct answer)
- Classifying all intelligence at the highest possible level
- Restricting access to intelligence products to one central office
Correct answer: Using multiple overlapping layers of security controls so a single failure does not compromise the whole system
Defense in depth employs multiple independent security layers so that when one control fails, others remain to contain the breach or threat.
Question 6: Which indicator would MOST elevate the assessed risk level of a previously low-priority threat group?
- Increased social media posts by group members
- Acquisition of weapons, financing, or recruitment of new members with operational skills (Correct answer)
- News coverage linking the group to past minor incidents
- A single confidential informant report without corroboration
Correct answer: Acquisition of weapons, financing, or recruitment of new members with operational skills
Capability acquisition — weapons, financing, skilled operatives — directly increases a group's ability to act, requiring immediate reassessment of their risk tier.
Question 7: Under the National Incident Management System (NIMS), risk management during a critical incident is primarily coordinated through:
- Individual agency risk officers acting independently
- The Incident Command System (ICS) unified command structure (Correct answer)
- Media liaison officers
- Federal Bureau of Investigation headquarters only
Correct answer: The Incident Command System (ICS) unified command structure
NIMS establishes ICS as the standardized framework for multi-agency coordination, including risk management decisions, during critical incidents.
When an analyst applies the 'all-hazards' approach to risk management, this means: