CPI CPI Risk Assessment & Threat Analysis 1 — Questions and Answers
Question 1: In risk assessment, how is 'risk' formally defined?
- The presence of any hazard on a property
- The product of threat likelihood and the impact (consequence) of that threat (Correct answer)
- The total cost of security equipment installed
- The number of incidents that occurred in the past year
Correct answer: The product of threat likelihood and the impact (consequence) of that threat
Risk is fundamentally calculated as the probability (likelihood) of a threat occurring multiplied by its potential consequence or impact.
Question 2: What is the difference between a 'threat' and a 'hazard' in security risk assessment terminology?
- They are interchangeable terms
- A threat is an intentional act by an adversary; a hazard is typically an unintentional or natural source of harm (Correct answer)
- A hazard is more serious than a threat
- A threat only applies to cyber incidents
Correct answer: A threat is an intentional act by an adversary; a hazard is typically an unintentional or natural source of harm
Threats are intentional acts (e.g., theft, sabotage) while hazards are unintentional or natural events (e.g., fire, flood, equipment failure).
Question 3: A CPI conducting a threat assessment identifies that a local activist group has publicly threatened a facility. This is an example of which threat category?
- Natural hazard
- Insider threat
- External adversarial threat (Correct answer)
- Accidental/unintentional hazard
Correct answer: External adversarial threat
A public threat from an external group is classified as an external adversarial threat, which requires specific countermeasures and monitoring.
Question 4: Which risk treatment option involves purchasing insurance or outsourcing to reduce financial exposure?
- Risk avoidance
- Risk acceptance
- Risk transference (Correct answer)
- Risk mitigation
Correct answer: Risk transference
Risk transference shifts the financial consequence of a risk to a third party, such as an insurer or contracted service provider.
Question 5: In a quantitative risk assessment, what does 'Annual Loss Expectancy (ALE)' represent?
- The total replacement cost of all assets
- The expected financial loss from a specific risk over a one-year period (Correct answer)
- The maximum possible loss in any single incident
- The annual budget allocated to security countermeasures
Correct answer: The expected financial loss from a specific risk over a one-year period
ALE is calculated as Single Loss Expectancy (SLE) multiplied by Annual Rate of Occurrence (ARO), representing expected yearly loss from a given risk.
Question 6: What is an 'insider threat' and why is it particularly challenging to address in risk assessments?
- A threat from adjacent businesses; it is challenging because of property lines
- A threat from employees, contractors, or trusted individuals who have authorized access; it is challenging because they bypass perimeter controls (Correct answer)
- A threat from building systems failures; challenging because of technical complexity
- A threat from foreign governments; challenging because of legal jurisdiction
Correct answer: A threat from employees, contractors, or trusted individuals who have authorized access; it is challenging because they bypass perimeter controls
Insider threats exploit legitimate access privileges, making them harder to detect than external threats since standard perimeter controls do not stop them.
In risk assessment, how is 'risk' formally defined?