CPI Risk Assessment & Threat Analysis Flashcards
6 cards from real CPI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CPI Risk Assessment & Threat Analysis flashcards as text
What is the 'bow-tie' analysis method used for in security risk assessments?
Answer: Visually mapping threat causes (left side) and consequences (right side) of a critical event, with controls on both sides
Bow-tie analysis maps prevention barriers (left) and recovery controls (right) around a central critical event, providing a comprehensive risk visualization.
Which federal framework is commonly referenced for risk assessment in critical infrastructure protection in the US?
Answer: NIST SP 800-30 and the NIPP (National Infrastructure Protection Plan)
NIST SP 800-30 provides a guide for risk assessment, and the NIPP provides the overarching framework for protecting US critical infrastructure from all hazards.
A CPI is assessing a school facility. A parent group recently posted social media threats against the principal. How should this be classified in the threat assessment?
Answer: Credible external adversarial threat requiring documented assessment, notification of law enforcement, and increased security posture
Social media threats must be treated as potentially credible, documented in the threat assessment, referred to law enforcement, and used to trigger enhanced security measures.
What does 'threat characterization' involve in a comprehensive security risk assessment?
Answer: Analyzing an adversary's capability, intent, and history to estimate the likelihood and method of an attack
Threat characterization examines adversary capability (can they do it?), intent (do they want to?), and history to produce a realistic threat likelihood estimate.
Which of the following best describes a 'red team' exercise in the context of a physical security risk assessment?
Answer: An authorized adversarial simulation where security professionals attempt to breach physical security to identify real vulnerabilities
A red team exercise simulates real attack methods against physical security controls to identify actual exploitable vulnerabilities under realistic conditions.
In risk assessment terminology, what is meant by 'risk appetite'?
Answer: The level of risk an organization is willing to accept in pursuit of its objectives
Risk appetite defines how much risk an organization is prepared to tolerate; it guides decisions about which risks require controls and which can be accepted.