← All CSS Flashcard Decks

Risk Evaluation & Threat Analysis Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Evaluation & Threat Analysis flashcards as text
  1. A security supervisor is conducting a risk assessment for a newly opened retail store. Which step should occur FIRST in the risk evaluation process?

    Answer: Identify assets to be protected

    Asset identification is the foundational first step in any risk evaluation because you cannot assess threats or vulnerabilities without knowing what needs protection.

  2. Which formula correctly expresses the relationship used to calculate risk in security management?

    Answer: Risk = Threat × Vulnerability × Asset Value

    Risk is determined by multiplying threat likelihood, vulnerability level, and the value of the asset at risk.

  3. A disgruntled employee who has inside knowledge of security procedures and access to restricted areas is best classified as what type of threat?

    Answer: Insider threat

    An insider threat involves individuals with authorized access who misuse that access to harm the organization.

  4. During a threat analysis, a security supervisor discovers that a competitor has been gathering intelligence on the company's operations. This is an example of which threat category?

    Answer: Corporate espionage

    Corporate espionage involves deliberate efforts by competitors or adversaries to gather proprietary business intelligence.

  5. A vulnerability assessment reveals that a server room has no secondary lock on the door. In risk terminology, this lack of protection is called a:

    Answer: Vulnerability

    A vulnerability is a weakness or gap in security measures that could be exploited by a threat to cause harm.

  6. When evaluating risks using a qualitative approach, a security supervisor would most likely use which tool?

    Answer: Risk rating matrix with High/Medium/Low categories

    Qualitative risk analysis uses descriptive scales such as High, Medium, and Low ratings rather than precise numerical calculations.

  7. A security supervisor observes that a parking garage has poor lighting, blind corners, and no CCTV coverage. These factors collectively increase which element of risk?

    Answer: Vulnerability level

    Physical deficiencies such as poor lighting and lack of surveillance increase the vulnerability of a location to attack or crime.

Risk Evaluation & Threat Analysis Flashcards — CSS Study Cards with Answers