Threat Evaluation & Risk Analysis Flashcards
7 cards from real CSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Evaluation & Risk Analysis flashcards as text
A risk analyst calculates that a warehouse has a 15% annual probability of experiencing cargo theft. This figure represents the:
Answer: Annualized rate of occurrence
The annualized rate of occurrence (ARO) expresses the estimated frequency with which a specific threat is expected to occur within a one-year period.
When evaluating threats in a high-rise office building, which factor would most significantly increase the vulnerability rating for the lobby?
Answer: Lack of visitor management system and open access to elevators
The absence of a visitor management system combined with unrestricted elevator access eliminates layered access control, dramatically increasing lobby vulnerability.
A threat evaluation matrix rates threat actors on capability and intent. An actor with HIGH capability but LOW intent should be classified as:
Answer: Moderate concern requiring monitoring but not immediate action
High capability with low intent warrants monitoring because intent can change, but does not yet justify the same countermeasure investment as a high-capability, high-intent actor.
During a risk assessment at a data center, the analyst identifies that backup power systems have not been tested in 18 months. This finding most directly affects which risk component?
Answer: Countermeasure effectiveness
Untested backup power systems cannot be relied upon, reducing the effectiveness of this countermeasure and increasing overall residual risk.
Social engineering attacks targeting employees with legitimate system access are most effectively countered at which risk mitigation level?
Answer: Personnel security and awareness training
Since social engineering exploits human behavior rather than physical or technical gaps, personnel security awareness training directly addresses the root vulnerability.
A risk register entry shows a threat with HIGH impact but VERY LOW likelihood. The recommended risk treatment strategy is typically:
Answer: Transfer the risk through insurance or contractual means
For high-impact, low-likelihood risks, risk transfer (such as insurance) is typically cost-effective because mitigation investment may exceed expected loss value.
A surveillance professional reviewing CCTV footage identifies an unknown individual accessing a server room using a valid badge. The most appropriate immediate action is:
Answer: Notify the access control administrator and security management
Immediately notifying access control administrators and security management enables a coordinated response and investigation while preserving evidence.