CIAC CIAC Threat Assessment & Risk Analysis 1 β Questions and Answers
Question 1: Which threat assessment model categorizes threats as LOW, MEDIUM, or HIGH based on capability and intent?
- The CARVER Matrix
- The Tiered Threat Model (Correct answer)
- The RAD Framework
- The SWOT Model
Correct answer: The Tiered Threat Model
The Tiered Threat Model organizes threats into LOW, MEDIUM, and HIGH categories by evaluating both actor capability and intent.
Question 2: What does the acronym 'CARVER' stand for in threat targeting analysis?
- Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability (Correct answer)
- Capability, Awareness, Risk, Vulnerability, Exposure, Response
- Criticality, Assessment, Risk, Value, Effect, Reach
- Capability, Access, Redundancy, Vulnerability, Evasion, Reach
Correct answer: Criticality, Accessibility, Recuperability, Vulnerability, Effect, Recognizability
CARVER stands for Criticality, Accessibility, Recuperability, Vulnerability, Effect, and Recognizability, and is used to prioritize potential targets.
Question 3: In crime intelligence, 'threat capability' refers to:
- The legal authority of a suspect
- The resources and skills a threat actor possesses to carry out an attack (Correct answer)
- The number of criminal associates in a network
- The geographic reach of a criminal organization
Correct answer: The resources and skills a threat actor possesses to carry out an attack
Threat capability specifically measures the resources, skills, and means an actor has available to execute a harmful act.
Question 4: Which framework is commonly used by US law enforcement to assess the risk posed by violent extremists?
- PESTLE Analysis
- The Behavioral Threat Assessment Model (Correct answer)
- SWOT Analysis
- The RICO Framework
Correct answer: The Behavioral Threat Assessment Model
The Behavioral Threat Assessment Model evaluates indicators, behaviors, and context to gauge the likelihood a violent extremist will act.
Question 5: A 'residual risk' in threat analysis is defined as:
- The primary risk before any countermeasures are applied
- The risk remaining after mitigation measures have been implemented (Correct answer)
- The risk transferred to another party through insurance
- The cumulative risk across all threat categories
Correct answer: The risk remaining after mitigation measures have been implemented
Residual risk is the level of risk that persists after all planned countermeasures and controls have been put in place.
Question 6: When conducting a risk assessment, 'vulnerability' most closely refers to:
- The probability that a threat actor will be apprehended
- A weakness in a system, process, or location that could be exploited (Correct answer)
- The severity of harm if an attack succeeds
- The frequency of past criminal incidents in an area
Correct answer: A weakness in a system, process, or location that could be exploited
Vulnerability identifies gaps or weaknesses that a threat actor could exploit to cause harm.
Which threat assessment model categorizes threats as LOW, MEDIUM, or HIGH based on capability and intent?