CSI Threat & Vulnerability Assessment 2 β Questions and Answers
Question 1: During a threat assessment, a security investigator identifies a disgruntled former employee who has retained access credentials. This situation is best classified as which type of threat?
- Environmental threat
- Insider threat (Correct answer)
- Cyber espionage
- Supply chain threat
Correct answer: Insider threat
A disgruntled former employee with retained access represents an insider threat, as the risk originates from someone with privileged knowledge of or access to the organization.
Question 2: Which methodology involves systematically walking through an organization's processes to identify points where threats could exploit weaknesses?
- Red team exercise
- Delphi method
- Threat modeling (Correct answer)
- Gap analysis
Correct answer: Threat modeling
Threat modeling is a structured approach that systematically identifies how threats could exploit system or process vulnerabilities.
Question 3: A CSI investigator is assessing a warehouse facility and notices the loading dock has no camera coverage and poor lighting after hours. What is the PRIMARY concern this represents?
- Policy gap
- Physical vulnerability (Correct answer)
- Procedural weakness
- Administrative risk
Correct answer: Physical vulnerability
Lack of camera coverage and poor lighting at a loading dock represents a physical vulnerability that could be exploited for theft, unauthorized entry, or other crimes.
Question 4: Which of the following best describes the concept of 'threat probability' in a vulnerability assessment?
- The total financial loss if a threat occurs
- The likelihood that a specific threat will materialize (Correct answer)
- The number of known threat actors targeting an organization
- The speed at which a threat can be neutralized
Correct answer: The likelihood that a specific threat will materialize
Threat probability refers to the likelihood or chance that a specific threat event will actually occur within a given time frame.
Question 5: An investigator conducting a vulnerability assessment discovers that security guards are skipping perimeter checks during the night shift. This is an example of what type of vulnerability?
- Technical vulnerability
- Procedural vulnerability (Correct answer)
- Environmental vulnerability
- Structural vulnerability
Correct answer: Procedural vulnerability
Skipping required security procedures represents a procedural vulnerability, where established protocols are not being followed.
Question 6: In threat assessment, the term 'target hardening' refers to:
- Training staff to respond aggressively to threats
- Increasing the difficulty for a threat actor to successfully attack an asset (Correct answer)
- Eliminating all identified vulnerabilities simultaneously
- Conducting background checks on all personnel
Correct answer: Increasing the difficulty for a threat actor to successfully attack an asset
Target hardening involves implementing measures that make it more difficult, costly, or risky for a threat actor to successfully attack or exploit an asset.
Question 7: A security investigator is performing an assessment at a financial institution. Which tool is MOST useful for systematically identifying and prioritizing asset vulnerabilities?
- SWOT analysis
- Risk matrix (Correct answer)
- Gantt chart
- Flow diagram
Correct answer: Risk matrix
A risk matrix allows investigators to systematically assess and prioritize vulnerabilities by plotting the likelihood of a threat against its potential impact.
During a threat assessment, a security investigator identifies a disgruntled former employee who has retained access credentials.
This situation is best classified as which type of threat?