โ† All CCSP Flashcard Decks

Security Threats & Risk Management Flashcards

7 cards from real CCSP practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Security Threats & Risk Management flashcards as text
  1. Which type of insider threat poses the greatest risk to cargo screening operations because they have legitimate access and knowledge of security procedures?

    Answer: Disgruntled employee with system credentials

    A disgruntled employee with system credentials combines authorized access, operational knowledge, and malicious intent โ€” the most dangerous insider threat combination.

  2. In risk management, what does the term 'residual risk' refer to?

    Answer: Risk that remains after all countermeasures are applied

    Residual risk is the remaining level of risk after security controls and countermeasures have been implemented.

  3. A shipper knowingly provides false cargo manifests to avoid screening. This scenario best represents which threat category?

    Answer: Deliberate deception / insider facilitation

    Providing false manifests is a deliberate act of deception that facilitates smuggling prohibited items past screening checkpoints.

  4. Which analytical method ranks threats by multiplying the likelihood of occurrence by the potential impact?

    Answer: Risk matrix scoring

    A risk matrix scores threats by multiplying probability (likelihood) by consequence (impact) to produce a prioritized risk ranking.

  5. Under the CCSP framework, what is the primary purpose of a vulnerability assessment?

    Answer: To identify weaknesses in security systems that adversaries could exploit

    A vulnerability assessment systematically identifies gaps and weaknesses in security posture that could be exploited by a threat actor.

  6. An air cargo facility receives a tip that a specific shipment may contain an IED. Which immediate action is MOST appropriate?

    Answer: Isolate the shipment, notify law enforcement, and follow the facility's emergency response plan

    Suspected IED threats require immediate isolation of the item, law enforcement notification, and activation of the emergency response plan to protect personnel and the facility.

  7. What is the key distinction between a threat and a hazard in the CCSP security context?

    Answer: A threat involves intentional hostile action; a hazard may be unintentional or accidental

    In security contexts, a threat implies intent to cause harm, while a hazard is a condition that may cause harm without necessarily involving deliberate action.

Security Threats & Risk Management Flashcards โ€” CCSP Study Cards with Answers