Threat Assessment & Risk Analysis Flashcards
7 cards from real CSC practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Assessment & Risk Analysis flashcards as text
When applying the NIST Risk Management Framework (RMF), at which step are security controls selected based on system categorization?
Answer: Select
The Select step in NIST RMF involves choosing security controls from NIST SP 800-53 appropriate to the system's categorization level.
A CSC is assessing insider threat risk. Which behavioral indicator is most strongly associated with data exfiltration intent?
Answer: Large-volume downloads shortly after submitting a resignation notice
Mass data downloads by an employee who has resigned is a classic precursor indicator of intellectual property theft.
Which formula correctly represents the fundamental risk calculation used in most qualitative frameworks?
Answer: Risk = Likelihood × Impact
Most qualitative risk frameworks calculate risk as the product of Likelihood (probability of occurrence) and Impact (severity of consequences).
A security consultant discovers that a critical industrial control system (ICS) has never been patched due to vendor restrictions. Which risk treatment is most appropriate?
Answer: Implement compensating controls such as network segmentation and enhanced monitoring
When patching is prohibited, compensating controls like network isolation and anomaly monitoring reduce risk without violating vendor restrictions.
Which kill chain phase does lateral movement most directly correspond to in the Lockheed Martin Cyber Kill Chain?
Answer: Actions on Objectives
Lateral movement occurs as adversaries expand access toward their target, which corresponds to the Actions on Objectives phase where they pursue their mission.
A CSC is quantifying risk for a financial services client. The organization experienced 3 breaches in 10 years, each costing $500,000. What is the Annualized Loss Expectancy (ALE)?
Answer: $150,000
ALE = ARO × SLE = (3/10) × $500,000 = 0.3 × $500,000 = $150,000.
In a threat modeling exercise, STRIDE is used to categorize threats. Which STRIDE category addresses threats that allow attackers to deny performing an action?
Answer: Repudiation
Repudiation threats (the R in STRIDE) involve attackers denying they performed actions when no audit trail or non-repudiation control exists.