โ† All CSI Flashcard Decks

Threat & Vulnerability Assessment Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Threat & Vulnerability Assessment flashcards as text
  1. An investigator conducting a threat assessment at a hospital identifies that pharmaceutical storage rooms are accessible with a master key held by 15 staff members. This finding is BEST categorized as:

    Answer: A key control vulnerability

    Excessive distribution of a master key to sensitive areas represents a key control vulnerability, which is a physical access control weakness.

  2. In threat assessment, 'surveillance detection' is a proactive measure designed to:

    Answer: Identify when a threat actor is conducting reconnaissance on a target

    Surveillance detection involves actively recognizing when a potential threat actor is observing or gathering information about a facility or individual, allowing for early intervention.

  3. A security investigator is advising on countermeasures for a specific vulnerability. The MOST cost-effective approach should:

    Answer: Prioritize countermeasures based on risk level and asset criticality

    Prioritizing countermeasures based on risk level and asset criticality ensures resources are allocated where they provide the greatest security benefit relative to cost.

  4. Which of the following BEST describes the role of 'threat intelligence' in a vulnerability assessment?

    Answer: It provides current and relevant information about known threat actors and emerging methods

    Threat intelligence provides actionable, current information about known threat actors, their tactics, and emerging methods to inform and enhance the accuracy of a vulnerability assessment.

  5. When documenting findings from a vulnerability assessment, why is it important to establish a clear chain of custody for the assessment data?

    Answer: To ensure the integrity and admissibility of findings if legal action arises

    Maintaining chain of custody for assessment data protects its integrity and ensures findings remain admissible as evidence if the matter proceeds to legal or regulatory action.

  6. A facility's vulnerability assessment reveals that employees regularly prop open emergency exit doors during break times. From a threat assessment perspective, this behavior:

    Answer: Creates an unauthorized access vulnerability that could be exploited by an adversary

    Propped emergency exit doors bypass access controls and create an unauthorized entry point that a threat actor could exploit, representing a significant physical security vulnerability.

  7. Which of the following MOST accurately describes a 'residual risk' in the context of a threat and vulnerability assessment?

    Answer: The risk that remains after all feasible countermeasures have been implemented

    Residual risk is the level of risk that remains after all practical and feasible countermeasures have been applied; it is the accepted remainder that cannot be fully eliminated.