Threat Assessment & Risk Analysis Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Assessment & Risk Analysis flashcards as text
A security consultant is asked to evaluate risks using a scenario-based approach rather than asset-based. Which methodology best fits this requirement?
Answer: Threat-centric risk assessment
Threat-centric risk assessment focuses on threat scenarios and adversary capabilities rather than starting from an asset inventory.
During a red team engagement, analysts discover the organization has no visibility into DNS query logs. This finding primarily affects which risk analysis component?
Answer: Threat likelihood estimation
Without DNS log visibility, analysts cannot accurately estimate the likelihood of DNS-based threats or detect active exfiltration.
The FAIR (Factor Analysis of Information Risk) model decomposes risk into Loss Event Frequency and which other primary factor?
Answer: Probable loss magnitude
FAIR defines risk as a function of Loss Event Frequency (LEF) and Probable Loss Magnitude (PLM).
A CSC is reviewing a client's risk register and notices that several risks are marked 'accepted' with no documented rationale. What is the primary concern?
Answer: Risk acceptance without documented rationale may violate governance and accountability requirements
Undocumented risk acceptance undermines accountability and may expose the organization to liability if the risk materializes.
Which threat intelligence source provides the highest confidence attribution for a nation-state advanced persistent threat (APT) group?
Answer: Strategic intelligence from government CERTs with classified backing
Government CERTs with access to classified signals intelligence provide the highest-confidence attribution for nation-state APTs.
A security consultant applies the Delphi method during a risk workshop. What is the primary benefit of this technique?
Answer: It reduces anchoring bias by collecting expert opinions anonymously in iterative rounds
The Delphi method gathers expert consensus through anonymous, iterative rounds to minimize groupthink and anchoring bias.
In a Business Impact Analysis (BIA), what does the Maximum Tolerable Downtime (MTD) metric define?
Answer: The longest period a business process can be disrupted before causing unacceptable harm
MTD (also called Maximum Tolerable Period of Disruption) is the upper boundary of disruption a process can sustain before consequences become unacceptable.