CCSP Security Threats & Risk Management 5 — Questions and Answers
Question 1: When conducting a security risk assessment, which step comes FIRST?
- Implementing countermeasures
- Identifying assets and their value (Correct answer)
- Conducting employee background checks
- Purchasing new detection equipment
Correct answer: Identifying assets and their value
Asset identification and valuation is the foundational first step because you must know what you are protecting before you can assess threats or vulnerabilities.
Question 2: A cargo facility discovers that its X-ray equipment has been producing degraded images for weeks due to a software fault. From a risk perspective, this represents:
- An accepted risk that was pre-planned
- An undetected vulnerability that increased threat exposure during the failure period (Correct answer)
- A transferred risk covered by the equipment warranty
- A residual risk that was intentionally tolerated
Correct answer: An undetected vulnerability that increased threat exposure during the failure period
An undetected equipment failure creates an unplanned vulnerability window, increasing the facility's actual threat exposure without awareness.
Question 3: Which term describes a coordinated effort by terrorist groups to probe security checkpoints through repeated low-level suspicious activity before launching a major attack?
- Blended threat
- Probing / surveillance attack (Correct answer)
- Denial of service
- Cascading failure
Correct answer: Probing / surveillance attack
Probing or surveillance involves testing security responses with minor incidents to gather intelligence for planning a larger, more effective attack.
Question 4: What is the primary role of intelligence sharing between cargo screening facilities and law enforcement agencies in risk management?
- To negotiate reduced screening fees
- To enable proactive identification and mitigation of emerging threats before they materialize (Correct answer)
- To transfer liability for missed threats to law enforcement
- To satisfy annual reporting requirements to the FAA
Correct answer: To enable proactive identification and mitigation of emerging threats before they materialize
Intelligence sharing allows facilities to act on threat information before an attack occurs, enabling proactive rather than purely reactive security.
Question 5: Which of the following BEST describes the concept of 'threat-based screening' used in cargo security?
- Screening every piece of cargo with identical intensity regardless of origin
- Adjusting screening methods and intensity based on the assessed risk level of specific cargo, shippers, or routes (Correct answer)
- Screening only cargo that exceeds a defined weight threshold
- Limiting screening to cargo arriving from non-allied countries
Correct answer: Adjusting screening methods and intensity based on the assessed risk level of specific cargo, shippers, or routes
Threat-based screening allocates resources dynamically, applying more intensive measures where intelligence and risk factors indicate elevated threat levels.
Question 6: A facility security officer notices that cargo from a new, unvetted shipper lacks proper documentation and the shipper is unable to provide satisfactory answers. The BEST action is:
- Accept the cargo with a notation in the manifest and screen it normally
- Refuse acceptance until documentation is verified and, if necessary, contact TSA and law enforcement (Correct answer)
- Allow the cargo through to avoid delaying the flight schedule
- Ask a coworker's opinion before taking any action
Correct answer: Refuse acceptance until documentation is verified and, if necessary, contact TSA and law enforcement
Unverified documentation from an unvetted shipper is a red flag requiring refusal and escalation to TSA and law enforcement rather than routine processing.
Question 7: In risk management terminology, what is the difference between 'risk likelihood' and 'risk probability'?
- They are identical terms with no meaningful distinction in security practice
- Likelihood is a qualitative estimate; probability is a quantitative statistical measure (Correct answer)
- Likelihood refers to natural disasters only; probability applies to man-made threats
- Probability is used only in insurance calculations, not security assessments
Correct answer: Likelihood is a qualitative estimate; probability is a quantitative statistical measure
In practice, likelihood is often expressed qualitatively (low/medium/high) while probability uses numerical data, though both measure how often a risk event may occur.
When conducting a security risk assessment, which step comes FIRST?