CDASA Threat Assessment and Risk Management 2 — Questions and Answers
Question 1: In the context of threat assessment, what does 'intent' refer to when evaluating an adversary?
- The adversary's technical capabilities to execute an attack
- The adversary's desire or plan to conduct a harmful action (Correct answer)
- The adversary's geographic proximity to the target
- The adversary's historical record of past attacks
Correct answer: The adversary's desire or plan to conduct a harmful action
Intent refers to an adversary's desire, will, or plan to conduct a harmful action against a target, distinct from their capability to do so.
Question 2: Which risk management framework is most commonly referenced in U.S. defense intelligence for assessing information system risks?
- ISO 31000
- NIST Risk Management Framework (RMF) (Correct answer)
- COSO ERM
- FAIR (Factor Analysis of Information Risk)
Correct answer: NIST Risk Management Framework (RMF)
The NIST Risk Management Framework (RMF) is the standard used across U.S. federal and defense organizations for managing information system security risks.
Question 3: A threat actor consistently targets logistics nodes before major operations. This pattern best illustrates which analytical concept?
- Indicator analysis
- Threat signature recognition
- Doctrinal pattern analysis (Correct answer)
- Predictive modeling
Correct answer: Doctrinal pattern analysis
Doctrinal pattern analysis examines an adversary's established methods and tactics to predict future behavior based on observed patterns.
Question 4: What is the primary purpose of a 'red team' in the context of risk management?
- To respond to active cyber intrusions
- To simulate adversary tactics and identify vulnerabilities from an attacker's perspective (Correct answer)
- To audit compliance with security policies
- To train blue team defenders in defensive techniques
Correct answer: To simulate adversary tactics and identify vulnerabilities from an attacker's perspective
A red team adopts the adversary's perspective to proactively identify weaknesses before real threat actors can exploit them.
Question 5: Which of the following best describes a 'residual risk' after countermeasures are applied?
- The total risk before any mitigation
- The risk that remains after controls are implemented (Correct answer)
- The risk transferred to a third-party insurer
- The risk accepted as part of normal operations without any controls
Correct answer: The risk that remains after controls are implemented
Residual risk is the remaining level of risk after security controls and countermeasures have been applied to reduce initial risk.
Question 6: In threat assessment, 'opportunity' as a factor means the adversary has:
- Financial resources to fund the attack
- Access or a viable attack vector to reach the target (Correct answer)
- Political motivation to conduct operations
- Media coverage that enables psychological operations
Correct answer: Access or a viable attack vector to reach the target
Opportunity refers to the adversary having access or a viable pathway to reach and affect the target, completing the intent-capability-opportunity triad.
Question 7: Which analytic product is specifically designed to warn decision-makers of imminent threats before they materialize?
- Strategic Intelligence Assessment
- Warning Intelligence (Correct answer)
- Current Intelligence Report
- Estimative Intelligence
Correct answer: Warning Intelligence
Warning intelligence is specifically produced to alert policymakers and commanders of impending hostile actions or threats requiring immediate attention.
In the context of threat assessment, what does 'intent' refer to when evaluating an adversary?