← All CSP Flashcard Decks

Threat Evaluation & Risk Analysis Flashcards

7 cards from real CSP practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat Evaluation & Risk Analysis flashcards as text
  1. A security manager applies a cost-benefit analysis to a proposed CCTV upgrade. Which outcome would justify the investment from a risk perspective?

    Answer: The projected annual loss reduction exceeds the total cost of the upgrade

    A security investment is justified when the projected loss reduction (risk reduction value) exceeds the total implementation and operational cost of the countermeasure.

  2. A threat assessment of a sports venue identifies crowd crush as a significant risk during sold-out events. This risk is best categorized as:

    Answer: Unintentional mass casualty hazard

    Crowd crush results from human behavior under density conditions rather than intentional malicious action, classifying it as an unintentional mass casualty hazard.

  3. Which approach to risk analysis requires the assessor to estimate the MAXIMUM CREDIBLE loss scenario rather than the average expected loss?

    Answer: Maximum probable loss (MPL) assessment

    Maximum probable loss (MPL) assessment focuses on the worst credible scenario rather than the statistical average, providing a ceiling figure for risk tolerance and insurance decisions.

  4. A surveillance analyst notices that a subject of interest has changed vehicles and clothing but continues to appear near the same facility. This pattern indicates:

    Answer: Active counter-surveillance awareness and continued threat intent

    Deliberately changing appearance and vehicles while continuing surveillance of the same target demonstrates counter-surveillance awareness, which actually elevates the threat assessment level.

  5. The concept of 'defense in depth' in physical security risk management refers to:

    Answer: Layering multiple independent security controls so that failure of one does not compromise overall security

    Defense in depth deploys multiple overlapping, independent security layers so that an attacker must defeat each successive layer, and failure of one control does not enable full compromise.

  6. When conducting a threat assessment for a financial institution, an analyst reviews recent incidents at comparable facilities nationwide. This practice is known as:

    Answer: Peer industry threat intelligence analysis

    Peer industry threat intelligence analysis uses incident data from similar organizations to identify emerging threat patterns and anticipate risks before they materialize locally.

  7. A risk analysis determines that a particular threat has a probability of 0.05 and a potential impact of $400,000. The annualized loss expectancy (ALE) for this threat is:

    Answer: $20,000

    ALE = probability × impact = 0.05 × $400,000 = $20,000, representing the average expected annual loss from this specific threat.