CSC Threat Assessment & Risk Analysis 2 — Questions and Answers
Question 1: A security consultant is asked to evaluate risks using a scenario-based approach rather than asset-based. Which methodology best fits this requirement?
- OCTAVE Allegro
- Threat-centric risk assessment (Correct answer)
- Quantitative asset valuation
- Control gap analysis
Correct answer: Threat-centric risk assessment
Threat-centric risk assessment focuses on threat scenarios and adversary capabilities rather than starting from an asset inventory.
Question 2: During a red team engagement, analysts discover the organization has no visibility into DNS query logs. This finding primarily affects which risk analysis component?
- Threat likelihood estimation (Correct answer)
- Asset valuation accuracy
- Vulnerability enumeration
- Control effectiveness measurement
Correct answer: Threat likelihood estimation
Without DNS log visibility, analysts cannot accurately estimate the likelihood of DNS-based threats or detect active exfiltration.
Question 3: The FAIR (Factor Analysis of Information Risk) model decomposes risk into Loss Event Frequency and which other primary factor?
- Threat capability
- Probable loss magnitude (Correct answer)
- Control deficiency score
- Vulnerability exposure window
Correct answer: Probable loss magnitude
FAIR defines risk as a function of Loss Event Frequency (LEF) and Probable Loss Magnitude (PLM).
Question 4: A CSC is reviewing a client's risk register and notices that several risks are marked 'accepted' with no documented rationale. What is the primary concern?
- Risk acceptance without documented rationale may violate governance and accountability requirements (Correct answer)
- Accepted risks should always be transferred to insurance instead
- Risk acceptance is never a valid response strategy
- The risk register format is non-compliant with ISO 31000
Correct answer: Risk acceptance without documented rationale may violate governance and accountability requirements
Undocumented risk acceptance undermines accountability and may expose the organization to liability if the risk materializes.
Question 5: Which threat intelligence source provides the highest confidence attribution for a nation-state advanced persistent threat (APT) group?
- OSINT social media monitoring
- Tactical threat indicators from ISACs
- Strategic intelligence from government CERTs with classified backing (Correct answer)
- Commercial dark web crawlers
Correct answer: Strategic intelligence from government CERTs with classified backing
Government CERTs with access to classified signals intelligence provide the highest-confidence attribution for nation-state APTs.
Question 6: A security consultant applies the Delphi method during a risk workshop. What is the primary benefit of this technique?
- It automates vulnerability scanning across enterprise assets
- It reduces anchoring bias by collecting expert opinions anonymously in iterative rounds (Correct answer)
- It assigns dollar values to intangible assets automatically
- It maps threat actors to MITRE ATT&CK techniques without analyst input
Correct answer: It reduces anchoring bias by collecting expert opinions anonymously in iterative rounds
The Delphi method gathers expert consensus through anonymous, iterative rounds to minimize groupthink and anchoring bias.
Question 7: In a Business Impact Analysis (BIA), what does the Maximum Tolerable Downtime (MTD) metric define?
- The time required to restore a system from backup
- The longest period a business process can be disrupted before causing unacceptable harm (Correct answer)
- The average annual cost of a security incident
- The frequency at which backups must be tested
Correct answer: The longest period a business process can be disrupted before causing unacceptable harm
MTD (also called Maximum Tolerable Period of Disruption) is the upper boundary of disruption a process can sustain before consequences become unacceptable.
A security consultant is asked to evaluate risks using a scenario-based approach rather than asset-based.
Which methodology best fits this requirement?