CPI CPI Risk Assessment & Threat Analysis 2 — Questions and Answers
Question 1: Which risk assessment methodology uses a 3×3 or 5×5 matrix to plot likelihood against consequence?
- Fault Tree Analysis (FTA)
- Qualitative Risk Matrix (Correct answer)
- Failure Mode and Effects Analysis (FMEA)
- Monte Carlo Simulation
Correct answer: Qualitative Risk Matrix
A qualitative risk matrix plots likelihood on one axis and consequence on the other to visually prioritize risks without requiring precise numerical data.
Question 2: A CPI is asked to assess the 'criticality' of assets during a risk assessment. What does criticality measure?
- The age and depreciation value of an asset
- The importance of an asset to the organization's mission and the impact if it were lost or compromised (Correct answer)
- The replacement cost of the asset only
- The physical dimensions and weight of the asset
Correct answer: The importance of an asset to the organization's mission and the impact if it were lost or compromised
Criticality reflects how essential an asset is to operations and how severely its loss would impact the organization's ability to function.
Question 3: What is 'vulnerability' in the context of a security risk assessment?
- The likelihood that a threat will occur
- A weakness or gap in security measures that could be exploited by a threat (Correct answer)
- The financial value of an asset at risk
- The organization's annual security budget
Correct answer: A weakness or gap in security measures that could be exploited by a threat
Vulnerability is a weakness or deficiency in physical, procedural, or technical security that increases the probability a threat can cause harm.
Question 4: During a threat analysis, a CPI reviews crime statistics for the area surrounding a facility. This activity supports which step of the risk assessment process?
- Asset valuation
- Threat identification and likelihood estimation (Correct answer)
- Countermeasure selection
- Risk acceptance documentation
Correct answer: Threat identification and likelihood estimation
Historical crime data provides an empirical basis for estimating the likelihood of criminal threats against a facility in a specific location.
Question 5: What is the primary purpose of a 'residual risk' evaluation after security countermeasures have been implemented?
- To determine how much security equipment remains in inventory
- To measure the risk that remains after controls have been applied, ensuring it is acceptable to the organization (Correct answer)
- To identify all new threats introduced by the countermeasures
- To calculate the ROI of security investments
Correct answer: To measure the risk that remains after controls have been applied, ensuring it is acceptable to the organization
Residual risk is the remaining exposure after controls are applied; it must be evaluated to confirm it falls within the organization's risk tolerance.
Question 6: A CPI finds that a chemical storage facility has no documented Business Continuity Plan (BCP). Why is this significant to the risk assessment?
- BCPs are only required for financial institutions
- Without a BCP, the organization cannot recover effectively from incidents, increasing the overall impact of any realized risk (Correct answer)
- BCPs are administrative documents with no impact on physical security
- The absence of a BCP only affects cybersecurity risks
Correct answer: Without a BCP, the organization cannot recover effectively from incidents, increasing the overall impact of any realized risk
A BCP reduces the consequence component of risk by ensuring the organization can maintain or quickly restore critical operations after a disruptive event.
Which risk assessment methodology uses a 3×3 or 5×5 matrix to plot likelihood against consequence?