CSI Threat Identification & Risk Management 2 — Questions and Answers
Question 1: Which risk assessment methodology uses probability and impact matrices to prioritize threats?
- Qualitative risk analysis (Correct answer)
- Quantitative risk analysis
- Residual risk analysis
- Inherent risk analysis
Correct answer: Qualitative risk analysis
Qualitative risk analysis uses probability and impact matrices to rank and prioritize threats without precise numerical values.
Question 2: A security investigator notices an employee repeatedly accessing files outside their job role at odd hours. This behavior is best classified as:
- External threat indicator
- Insider threat indicator (Correct answer)
- Physical security breach
- Social engineering attempt
Correct answer: Insider threat indicator
Accessing files beyond one's job scope during unusual hours is a classic insider threat behavioral indicator.
Question 3: What does 'residual risk' refer to in a security context?
- Risk that has been fully eliminated
- Risk remaining after controls are applied (Correct answer)
- Risk transferred to an insurer
- Risk identified but not yet assessed
Correct answer: Risk remaining after controls are applied
Residual risk is the level of risk that remains after security controls and countermeasures have been implemented.
Question 4: Which of the following is a PRIMARY goal of a threat vulnerability assessment?
- Identify suspects in a crime
- Determine which assets face the greatest exposure (Correct answer)
- Document incident response procedures
- Train security personnel on new policies
Correct answer: Determine which assets face the greatest exposure
A threat vulnerability assessment aims to identify which assets are most exposed to identified threats.
Question 5: In the context of risk management, 'risk acceptance' means:
- Transferring risk to a third party
- Implementing controls to reduce risk
- Acknowledging risk exists and choosing not to mitigate it further (Correct answer)
- Eliminating the activity that causes the risk
Correct answer: Acknowledging risk exists and choosing not to mitigate it further
Risk acceptance is a deliberate decision to tolerate an identified risk without additional mitigation, typically when the cost of control exceeds the potential loss.
Question 6: A 'threat agent' in security risk terminology refers to:
- A government law enforcement officer
- The entity capable of exploiting a vulnerability (Correct answer)
- A monitoring software system
- An automated security control
Correct answer: The entity capable of exploiting a vulnerability
A threat agent is any person, group, or force with the capability and intent to exploit a vulnerability.
Question 7: Which risk treatment strategy involves purchasing insurance to cover potential losses from a security incident?
- Risk mitigation
- Risk avoidance
- Risk transfer (Correct answer)
- Risk acceptance
Correct answer: Risk transfer
Risk transfer shifts the financial burden of a potential loss to another party, most commonly through insurance.
Which risk assessment methodology uses probability and impact matrices to prioritize threats?