Threat Evaluation & Risk Analysis Flashcards
7 cards from real CSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Evaluation & Risk Analysis flashcards as text
Which term describes the remaining risk after all planned countermeasures have been implemented?
Answer: Residual risk
Residual risk is the level of risk that persists after countermeasures are applied, and it must be consciously accepted, transferred, or further mitigated by management.
A threat assessment team uses structured interviews with subject matter experts to reach consensus on threat probabilities when historical data is scarce. This technique is called the:
Answer: Delphi method
The Delphi method uses iterative rounds of expert questionnaires and feedback to reach structured consensus, particularly useful when empirical data is limited.
A hotel surveillance team detects a guest repeatedly photographing emergency exit locations and stairwell access points. Under threat assessment protocols, this behavior should trigger:
Answer: Documentation, increased monitoring, and notification to management and law enforcement liaison
Photographing emergency exits and stairwells is a recognized pre-attack surveillance indicator requiring documentation, escalated monitoring, and appropriate notification.
The 'design basis threat' (DBT) concept is primarily used in which sector's risk analysis process?
Answer: Nuclear and critical infrastructure security
The design basis threat is a regulatory concept in nuclear and critical infrastructure security that defines the reference threat against which protective systems are designed and evaluated.
During a vulnerability assessment, a security analyst finds that motion sensors in a warehouse have 8-second reset delays after activation. This finding represents a:
Answer: Countermeasure gap or detection blind spot
An 8-second sensor reset delay creates a window during which motion can occur without triggering an alert, constituting a detection gap in the security system.
Risk prioritization matrices typically plot threats on axes representing:
Answer: Likelihood of occurrence vs. magnitude of impact
Standard risk matrices use likelihood (probability of occurrence) on one axis and impact (magnitude of consequences) on the other to visually prioritize threats.
A surveillance professional is asked to assess the threat posed by organized retail crime (ORC) groups. Which data source would provide the MOST operationally relevant threat intelligence?
Answer: Regional law enforcement ORC bulletins and retailer loss prevention network alerts
Regional law enforcement ORC bulletins and retail loss prevention network alerts contain specific, timely intelligence about active groups operating in the relevant geographic area.