Threat Assessment & Risk Analysis Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Assessment & Risk Analysis flashcards as text
A security consultant is tasked with prioritizing vulnerabilities across 500 systems. Which scoring system provides the most standardized basis for prioritization?
Answer: Common Vulnerability Scoring System (CVSS)
CVSS provides a standardized, vendor-neutral numerical score (0–10) enabling consistent cross-system vulnerability prioritization.
Which risk analysis approach produces dollar-value outputs and enables direct cost-benefit analysis of security controls?
Answer: Quantitative risk analysis
Quantitative risk analysis assigns monetary values to assets, threats, and controls, producing numerical risk outputs that support cost-benefit decisions.
A physical security assessment reveals that a data center's perimeter fence has a gap. Using the concentric rings model, which protection layer has failed?
Answer: Outer perimeter layer
In the concentric rings (defense-in-depth) physical security model, the outer perimeter (site boundary fence) is the first protective layer.
During a risk assessment, a CSC identifies a threat with high likelihood but very low impact. Which risk response is typically most appropriate?
Answer: Accept or monitor the risk given its low consequence
A high-likelihood, low-impact risk generally falls below the risk threshold requiring active treatment and is best accepted with monitoring.
Which threat category does supply chain compromise most closely represent in the NIST SP 800-30 threat taxonomy?
Answer: Adversarial threat — trusted insider/third party
Supply chain attacks exploit trusted third-party relationships, classifying them as adversarial threats initiated through trusted insiders or vendors per NIST SP 800-30.
A CSC applies attack tree analysis to a physical security scenario. What is the root node of an attack tree?
Answer: The attacker's ultimate goal or objective
In attack trees, the root node represents the attacker's ultimate objective, with branches representing ways to achieve that goal.
When calculating residual risk after implementing a control, which statement is most accurate?
Answer: Residual risk is inherent risk minus the risk reduction achieved by controls
Residual risk is the risk remaining after controls are applied, calculated as inherent risk minus the reduction provided by those controls.