← All CSI Flashcard Decks

Threat & Vulnerability Assessment Flashcards

7 cards from real CSI practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Threat & Vulnerability Assessment flashcards as text
  1. During a threat assessment, a security investigator identifies a disgruntled former employee who has retained access credentials. This situation is best classified as which type of threat?

    Answer: Insider threat

    A disgruntled former employee with retained access represents an insider threat, as the risk originates from someone with privileged knowledge of or access to the organization.

  2. Which methodology involves systematically walking through an organization's processes to identify points where threats could exploit weaknesses?

    Answer: Threat modeling

    Threat modeling is a structured approach that systematically identifies how threats could exploit system or process vulnerabilities.

  3. A CSI investigator is assessing a warehouse facility and notices the loading dock has no camera coverage and poor lighting after hours. What is the PRIMARY concern this represents?

    Answer: Physical vulnerability

    Lack of camera coverage and poor lighting at a loading dock represents a physical vulnerability that could be exploited for theft, unauthorized entry, or other crimes.

  4. Which of the following best describes the concept of 'threat probability' in a vulnerability assessment?

    Answer: The likelihood that a specific threat will materialize

    Threat probability refers to the likelihood or chance that a specific threat event will actually occur within a given time frame.

  5. An investigator conducting a vulnerability assessment discovers that security guards are skipping perimeter checks during the night shift. This is an example of what type of vulnerability?

    Answer: Procedural vulnerability

    Skipping required security procedures represents a procedural vulnerability, where established protocols are not being followed.

  6. In threat assessment, the term 'target hardening' refers to:

    Answer: Increasing the difficulty for a threat actor to successfully attack an asset

    Target hardening involves implementing measures that make it more difficult, costly, or risky for a threat actor to successfully attack or exploit an asset.

  7. A security investigator is performing an assessment at a financial institution. Which tool is MOST useful for systematically identifying and prioritizing asset vulnerabilities?

    Answer: Risk matrix

    A risk matrix allows investigators to systematically assess and prioritize vulnerabilities by plotting the likelihood of a threat against its potential impact.