CDASA Threat Assessment and Risk Management 3 β Questions and Answers
Question 1: When conducting a threat assessment for a military installation, which element is NOT typically part of the threat definition?
- Adversary capabilities
- Adversary intentions
- Installation's budget cycle (Correct answer)
- Adversary past activities
Correct answer: Installation's budget cycle
Threat assessment focuses on adversary characteristics (capabilities, intentions, past activities), not on friendly-force administrative factors like budget cycles.
Question 2: The 'likelihood' component of risk is most accurately defined as:
- The severity of damage if a threat succeeds
- The probability that a threat will exploit a vulnerability (Correct answer)
- The cost of implementing countermeasures
- The number of adversaries capable of conducting an attack
Correct answer: The probability that a threat will exploit a vulnerability
Likelihood (or probability) measures how probable it is that a given threat will successfully exploit an existing vulnerability within a specific timeframe.
Question 3: Which method involves systematically identifying what could go wrong and the consequences of each failure in a system or plan?
- SWOT Analysis
- Failure Mode and Effects Analysis (FMEA) (Correct answer)
- PESTLE Analysis
- Critical Node Analysis
Correct answer: Failure Mode and Effects Analysis (FMEA)
FMEA is a structured approach to identifying all possible failure modes in a system, their causes, and their effects on system operation.
Question 4: A nation-state actor is assessed as having advanced cyber capabilities but no current intent to attack U.S. infrastructure. This is best characterized as:
- An active threat
- A latent threat (Correct answer)
- A residual threat
- An accepted risk
Correct answer: A latent threat
A latent threat exists when an adversary has the capability to cause harm but currently lacks the intent or opportunity to act on that capability.
Question 5: In risk management, 'risk transfer' is best exemplified by:
- Installing additional firewalls to reduce cyber exposure
- Accepting the risk and continuing operations unchanged
- Purchasing cyber insurance to shift financial liability (Correct answer)
- Eliminating the vulnerable system entirely
Correct answer: Purchasing cyber insurance to shift financial liability
Risk transfer shifts the financial or operational burden of a risk to another party, most commonly through insurance or contractual agreements.
Question 6: What analytical technique compares the cost of implementing a security countermeasure against the expected loss it prevents?
- Risk appetite analysis
- Cost-benefit analysis (CBA) (Correct answer)
- Threat matrix scoring
- Vulnerability prioritization
Correct answer: Cost-benefit analysis (CBA)
Cost-benefit analysis determines whether the investment in a countermeasure is justified by comparing its cost to the risk reduction (avoided loss) it provides.
Question 7: Which threat category encompasses non-state actors motivated primarily by ideological or political goals rather than financial gain?
- Cybercriminals
- Hacktivists (Correct answer)
- Insider threats
- Corporate espionage actors
Correct answer: Hacktivists
Hacktivists are non-state threat actors whose primary motivation is advancing a political, social, or ideological agenda rather than monetary profit.
When conducting a threat assessment for a military installation, which element is NOT typically part of the threat definition?