UDEE Critical Thinking and Analysis 3 — Questions and Answers
Question 1: An intelligence brief states: 'There is a medium probability that a protest will occur outside the facility on Friday.' What does 'medium probability' MOST appropriately indicate for planning purposes?
- The protest will definitely occur and full resources should be deployed
- The protest is unlikely and normal staffing is sufficient
- The possibility is significant enough to warrant contingency planning while maintaining normal operations (Correct answer)
- The intelligence is unreliable and should be disregarded
Correct answer: The possibility is significant enough to warrant contingency planning while maintaining normal operations
Medium probability warrants contingency planning and preparation without full resource deployment, which would be reserved for high-probability threats.
Intelligence-based planning uses probability assessments to calibrate resource deployment. 'Medium probability' means the event is plausible and has meaningful supporting intelligence — not certain, but not dismissible. The appropriate response is contingency planning: pre-position additional resources, brief supervisors, develop response protocols — while maintaining normal operations. Over-responding to medium threats depletes resources; under-responding creates vulnerabilities.
Question 2: Officers receive these facts: (1) Only credentialed staff may access Level 3. (2) A fingerprint scan is required for Level 3 entry. (3) Officer Walsh accessed Level 3 at 0145. What can be DEFINITIVELY concluded?
- Officer Walsh has a credential AND their fingerprint was scanned (Correct answer)
- Officer Walsh bypassed security
- Officer Walsh is a supervisor
- The fingerprint scanner malfunctioned
Correct answer: Officer Walsh has a credential AND their fingerprint was scanned
Both conditions (credential + fingerprint scan) must be met to access Level 3. If Walsh accessed it, both conditions were satisfied.
Deductive logic: accessing Level 3 requires (1) credential AND (2) fingerprint scan. If Walsh accessed Level 3, then by logical necessity both conditions were satisfied. This is modus ponens applied conjunctively. We cannot conclude bypass, supervisory rank, or equipment malfunction from these facts alone — those would require additional evidence. The only definitive conclusion from the given premises is that Walsh had both a credential and a successful fingerprint scan.
Question 3: A supervisor reviews incident data from the past year showing that 73% of unauthorized access attempts occurred between 2200 and 0200. The supervisor should MOST appropriately:
- Increase patrol intensity during 2200–0200 and consider additional countermeasures for that window (Correct answer)
- Redistribute security resources evenly throughout the day to prevent complacency
- Conclude that the facility is safe during daytime hours
- Disregard the data as statistically unreliable with only one year of records
Correct answer: Increase patrol intensity during 2200–0200 and consider additional countermeasures for that window
Data showing 73% of incidents in a 4-hour window provides strong evidence for targeted resource allocation during that high-risk period.
Evidence-based security management uses incident data to optimize resource deployment. A 73% concentration in a 4-hour window (2200–0200) is a substantial, actionable pattern. Increasing patrol intensity and deploying countermeasures during this window is the most logical response. Redistributing evenly ignores the pattern. Concluding daytime is safe overstates the implication. One year of consistent data is statistically meaningful for operational planning purposes.
Question 4: Two officers submit conflicting reports about the timing of an event. Officer A states the event occurred at 1515; Officer B states it occurred at 1530. Both officers were present. The MOST appropriate interpretation is:
- Officer A is correct because they reported first
- Officer B is correct because they seem more experienced
- The discrepancy is minor and can be dismissed
- The discrepancy should be documented and both officers interviewed to determine the accurate timeline (Correct answer)
Correct answer: The discrepancy should be documented and both officers interviewed to determine the accurate timeline
Even a 15-minute discrepancy can be significant in security incidents; conflicting reports require investigation to establish the accurate timeline.
In security and legal contexts, even small timing discrepancies can affect the integrity of an investigation, the establishment of alibis, and the sequence of events. Neither report should be dismissed in favor of the other based on who reported first or subjective credibility assessments. The proper procedure is to document the discrepancy, interview both officers with open-ended questions, review corroborating evidence (CCTV timestamps, access logs), and establish the accurate timeline.
Question 5: A security analyst notes that over the past month, three attempts to access a particular server room all occurred within 10 minutes of a shift change. What does this pattern MOST likely suggest?
- The server room's lock is malfunctioning at regular intervals
- The threat actor may have knowledge of shift schedules and is exploiting the transition period (Correct answer)
- The server room access attempts are coincidental
- The shift change schedule should be extended
Correct answer: The threat actor may have knowledge of shift schedules and is exploiting the transition period
A pattern linked to shift changes suggests the threat actor knows the schedule and is deliberately exploiting the brief vulnerability during personnel transitions.
Shift changes create brief security vulnerabilities: outgoing officers are wrapping up, incoming officers are orienting, communication gaps exist. A consistent pattern of access attempts during this window strongly suggests an insider threat or a well-informed external actor exploiting this known vulnerability. This analysis should trigger schedule randomization, overlap protocols, and an insider threat investigation. Three consistent incidents rule out coincidence as a likely explanation.
Question 6: An officer is reviewing a grant of access for a new employee. The HR database shows the employee was cleared for Level 2 access. The physical access log shows the employee has been accessing Level 3. What should the officer do FIRST?
- Assume there was a data entry error in the HR database
- Immediately revoke the employee's access badge
- Verify whether Level 3 access was properly authorized through a separate channel and has not yet been updated in HR records (Correct answer)
- Report the discrepancy to IA as a security breach
Correct answer: Verify whether Level 3 access was properly authorized through a separate channel and has not yet been updated in HR records
Before taking enforcement action, the officer should verify whether the access was legitimately authorized but not yet reflected in the database — a common administrative lag.
Security investigations require verifying information from multiple sources before drawing conclusions. Database records sometimes lag behind operational authorizations — the employee may have received verbal or documented Level 3 authorization that hasn't been entered in HR records yet. The first step is cross-referencing with the authorizing supervisor or security officer. If unauthorized access is confirmed after verification, then escalation is appropriate. Acting on a single data source without verification can cause unjust enforcement actions.
An intelligence brief states: 'There is a medium probability that a protest will occur outside the facility on Friday.' What does 'medium probability' MOST appropriately indicate for planning purposes?