CSI Threat & Vulnerability Assessment 3 — Questions and Answers
Question 1: Which of the following is an example of a 'dynamic threat' as opposed to a 'static threat'?
- A building with an aging fire suppression system
- An organized crime group that adapts its tactics over time (Correct answer)
- A structural flaw in a perimeter fence
- A poorly lit stairwell
Correct answer: An organized crime group that adapts its tactics over time
An organized crime group that changes its tactics represents a dynamic threat because the threat actor adapts, making static defenses less effective over time.
Question 2: During a vulnerability assessment, an investigator should assess 'single points of failure' because they:
- Are always the most expensive assets to protect
- Represent locations where one failure can disable an entire security system (Correct answer)
- Indicate poor management practices
- Are only relevant in cybersecurity contexts
Correct answer: Represent locations where one failure can disable an entire security system
Single points of failure are critical weaknesses where one failure or compromise can bring down an entire security function or system.
Question 3: Which threat assessment model categorizes threats by intent, capability, and opportunity?
- CARVER matrix
- The threat triad (Correct answer)
- PESTLE analysis
- Bowtie model
Correct answer: The threat triad
The threat triad evaluates threats by examining whether an actor has the intent, capability, and opportunity to carry out an attack.
Question 4: A security investigator is tasked with assessing vulnerabilities at a corporate headquarters. Reviewing badge access logs for anomalies would PRIMARILY address which type of vulnerability?
- Physical access control gaps (Correct answer)
- Environmental hazards
- Cybersecurity weaknesses
- Supply chain risks
Correct answer: Physical access control gaps
Analyzing badge access logs helps identify unauthorized or anomalous physical access patterns, directly addressing physical access control vulnerabilities.
Question 5: What is the purpose of conducting a 'red team' exercise during a security vulnerability assessment?
- To train security staff in first aid response
- To simulate adversarial attacks and test actual defenses (Correct answer)
- To audit financial records for fraud indicators
- To review policy documentation for compliance
Correct answer: To simulate adversarial attacks and test actual defenses
A red team exercise simulates real-world adversarial attacks to test how effectively existing security measures can detect and resist threats.
Question 6: Which of the following is MOST characteristic of a 'motivated' threat actor?
- They possess advanced technical equipment
- They have a clear reason or goal driving their actions against a target (Correct answer)
- They are always affiliated with organized criminal groups
- They operate exclusively during business hours
Correct answer: They have a clear reason or goal driving their actions against a target
Motivation is the driving force behind a threat actor's actions; a motivated actor has a clear reason—financial gain, ideology, revenge—for targeting a specific asset.
Question 7: In a vulnerability assessment, 'consequence analysis' is performed to:
- Identify who is responsible for each security gap
- Determine the potential impact if a specific vulnerability is exploited (Correct answer)
- Calculate the cost of security upgrades
- Document the history of past security incidents
Correct answer: Determine the potential impact if a specific vulnerability is exploited
Consequence analysis evaluates the potential impact—financial, operational, reputational, or human—that would result if a specific vulnerability were successfully exploited.
Which of the following is an example of a 'dynamic threat' as opposed to a 'static threat'?