CSI Threat Identification & Risk Management 3 — Questions and Answers
Question 1: During a vulnerability assessment, a security investigator discovers an unlocked server room. This finding represents:
- A threat
- A vulnerability (Correct answer)
- A risk
- An exploit
Correct answer: A vulnerability
An unlocked server room is a vulnerability — a weakness that could be exploited by a threat actor.
Question 2: Which threat category encompasses acts of nature such as floods, earthquakes, and hurricanes?
- Adversarial threats
- Accidental threats
- Environmental threats (Correct answer)
- Structural threats
Correct answer: Environmental threats
Environmental threats include natural disasters and acts of nature that can impact organizational security.
Question 3: A security investigator is conducting a Business Impact Analysis (BIA). What is the PRIMARY output of a BIA?
- A list of potential threat actors
- Prioritized critical business functions and recovery time objectives (Correct answer)
- A physical security upgrade plan
- Employee background check requirements
Correct answer: Prioritized critical business functions and recovery time objectives
A BIA identifies critical business functions and establishes the maximum tolerable downtime and recovery objectives for each.
Question 4: What type of threat involves a malicious insider gradually increasing their access privileges over time without authorization?
- Privilege escalation (Correct answer)
- Lateral movement
- Social engineering
- Phishing
Correct answer: Privilege escalation
Privilege escalation involves an insider or attacker gaining higher-level access rights than they are authorized to have.
Question 5: In a security risk matrix, which combination represents the HIGHEST priority for immediate action?
- Low likelihood / High impact
- High likelihood / Low impact
- High likelihood / High impact (Correct answer)
- Low likelihood / Low impact
Correct answer: High likelihood / High impact
High likelihood combined with high impact places a risk in the critical zone, requiring immediate mitigation efforts.
Question 6: A company relies on a single supplier for a critical component. A CSI would flag this as which type of risk?
- Reputational risk
- Single point of failure / supply chain risk (Correct answer)
- Regulatory compliance risk
- Physical security risk
Correct answer: Single point of failure / supply chain risk
Dependence on a single supplier creates a single point of failure and supply chain vulnerability that could disrupt operations.
Question 7: Which of the following BEST describes 'threat intelligence' in security investigations?
- Wiretapping suspects to gather evidence
- Collecting and analyzing information about current and emerging threats (Correct answer)
- Training employees on security awareness
- Conducting physical surveillance of buildings
Correct answer: Collecting and analyzing information about current and emerging threats
Threat intelligence involves gathering, analyzing, and acting on information about threats to improve security decision-making.
During a vulnerability assessment, a security investigator discovers an unlocked server room.
This finding represents: