Threat Identification & Risk Management Flashcards
7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.
Read the first 7 Threat Identification & Risk Management flashcards as text
Which of the following scenarios BEST exemplifies a 'blended threat'?
Answer: An attacker using both social engineering and malware to breach a facility
A blended threat combines multiple attack vectors — in this case, social engineering and technical exploitation — to increase the chance of success.
A CSI is asked to assess the risk posed by disgruntled former employees. Which control MOST directly addresses this threat?
Answer: Immediately revoking all access credentials upon separation
Immediately terminating access credentials upon employee separation is the most direct control against unauthorized access by former employees.
What is the primary distinction between a 'threat' and a 'hazard' in security risk terminology?
Answer: Threats imply intentional harm; hazards are generally unintentional or environmental
Threats typically imply intentional or adversarial action, while hazards are generally unintentional conditions or environmental factors.
A security investigator is reviewing access logs and discovers an authorized user downloaded 50,000 customer records in one session. This is BEST described as:
Answer: A potential data exfiltration event requiring investigation
An unusually large download of sensitive records by an authorized user is an anomaly that warrants investigation as a potential data exfiltration or insider threat incident.
In risk management, 'defense in depth' refers to:
Answer: Layering multiple independent security controls so that failure of one does not compromise the system
Defense in depth is a strategy that employs multiple layers of security controls, ensuring no single point of failure can compromise the entire system.
Which document formally defines the acceptable level of risk an organization is willing to tolerate?
Answer: Risk Appetite Statement
A Risk Appetite Statement defines the amount and type of risk an organization's leadership is willing to accept in pursuit of its objectives.
A security investigator discovers that a critical facility has no documented threat assessment on file. The BEST immediate recommendation is to:
Answer: Commission a formal threat and vulnerability assessment
Without a formal threat and vulnerability assessment, security decisions lack a risk-based foundation, making one the top priority.