Risk Evaluation & Threat Analysis Flashcards
7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Risk Evaluation & Threat Analysis flashcards as text
A security supervisor is asked to distinguish between a 'hazard' and a 'threat' during a risk briefing. Which statement is MOST accurate?
Answer: Threats involve human intent; hazards are conditions with potential to cause harm without intent
A threat typically involves intentional human action, while a hazard is a condition — natural or accidental — that has the potential to cause harm without intent.
Which of the following scenarios represents an 'opportunity-based' threat rather than a 'targeted' threat?
Answer: A burglar who notices an unlocked door and spontaneously enters a facility
Opportunity-based threats arise when an offender exploits an unplanned vulnerability they encounter, rather than conducting advance planning against a specific target.
A CSS supervisor is updating a risk register. What information should a risk register primarily contain?
Answer: Identified risks, their likelihood, impact, owner, and mitigation status
A risk register is a documented record of identified risks, their assessed probability and impact, responsible owners, and the status of mitigation actions.
During a threat analysis workshop, a supervisor asks participants to imagine ways an adversary could defeat current security measures. This brainstorming technique is called:
Answer: Red team analysis
Red team analysis involves thinking and acting like an adversary to identify weaknesses and gaps in existing security measures.
A supervisor discovers that a data center has a single point of failure in its power supply. In a risk context, a single point of failure is a:
Answer: Vulnerability that, if exploited, would cause total system failure
A single point of failure is a critical vulnerability where failure of one component results in the failure of the entire system or operation.
A security supervisor is evaluating the risk posed by civil unrest near a corporate office. Which factor would MOST influence the severity rating of this threat?
Answer: The proximity of the unrest to the facility and the facility's profile as a potential target
Severity is most influenced by how close the threat is to the asset and whether the asset is a plausible or symbolic target for those causing unrest.
Which risk treatment option involves completely removing an activity or asset to eliminate the associated risk?
Answer: Risk avoidance
Risk avoidance eliminates risk entirely by discontinuing the activity, removing the asset, or changing the plan that creates the exposure.