Security Threats & Risk Management Flashcards
7 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Security Threats & Risk Management flashcards as text
When conducting a security risk assessment, which step comes FIRST?
Answer: Identifying assets and their value
Asset identification and valuation is the foundational first step because you must know what you are protecting before you can assess threats or vulnerabilities.
A cargo facility discovers that its X-ray equipment has been producing degraded images for weeks due to a software fault. From a risk perspective, this represents:
Answer: An undetected vulnerability that increased threat exposure during the failure period
An undetected equipment failure creates an unplanned vulnerability window, increasing the facility's actual threat exposure without awareness.
Which term describes a coordinated effort by terrorist groups to probe security checkpoints through repeated low-level suspicious activity before launching a major attack?
Answer: Probing / surveillance attack
Probing or surveillance involves testing security responses with minor incidents to gather intelligence for planning a larger, more effective attack.
What is the primary role of intelligence sharing between cargo screening facilities and law enforcement agencies in risk management?
Answer: To enable proactive identification and mitigation of emerging threats before they materialize
Intelligence sharing allows facilities to act on threat information before an attack occurs, enabling proactive rather than purely reactive security.
Which of the following BEST describes the concept of 'threat-based screening' used in cargo security?
Answer: Adjusting screening methods and intensity based on the assessed risk level of specific cargo, shippers, or routes
Threat-based screening allocates resources dynamically, applying more intensive measures where intelligence and risk factors indicate elevated threat levels.
A facility security officer notices that cargo from a new, unvetted shipper lacks proper documentation and the shipper is unable to provide satisfactory answers. The BEST action is:
Answer: Refuse acceptance until documentation is verified and, if necessary, contact TSA and law enforcement
Unverified documentation from an unvetted shipper is a red flag requiring refusal and escalation to TSA and law enforcement rather than routine processing.
In risk management terminology, what is the difference between 'risk likelihood' and 'risk probability'?
Answer: Likelihood is a qualitative estimate; probability is a quantitative statistical measure
In practice, likelihood is often expressed qualitatively (low/medium/high) while probability uses numerical data, though both measure how often a risk event may occur.