CPI Risk Assessment & Threat Analysis Flashcards
6 cards from real CPI practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 6 CPI Risk Assessment & Threat Analysis flashcards as text
In risk assessment, how is 'risk' formally defined?
Answer: The product of threat likelihood and the impact (consequence) of that threat
Risk is fundamentally calculated as the probability (likelihood) of a threat occurring multiplied by its potential consequence or impact.
What is the difference between a 'threat' and a 'hazard' in security risk assessment terminology?
Answer: A threat is an intentional act by an adversary; a hazard is typically an unintentional or natural source of harm
Threats are intentional acts (e.g., theft, sabotage) while hazards are unintentional or natural events (e.g., fire, flood, equipment failure).
A CPI conducting a threat assessment identifies that a local activist group has publicly threatened a facility. This is an example of which threat category?
Answer: External adversarial threat
A public threat from an external group is classified as an external adversarial threat, which requires specific countermeasures and monitoring.
Which risk treatment option involves purchasing insurance or outsourcing to reduce financial exposure?
Answer: Risk transference
Risk transference shifts the financial consequence of a risk to a third party, such as an insurer or contracted service provider.
In a quantitative risk assessment, what does 'Annual Loss Expectancy (ALE)' represent?
Answer: The expected financial loss from a specific risk over a one-year period
ALE is calculated as Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing expected yearly loss from a given risk.
What is an 'insider threat' and why is it particularly challenging to address in risk assessments?
Answer: A threat from employees, contractors, or trusted individuals who have authorized access; it is challenging because they bypass perimeter controls
Insider threats exploit legitimate access privileges, making them harder to detect than external threats since standard perimeter controls do not stop them.