Threat Evaluation & Risk Analysis Flashcards
7 cards from real CSP practice questions. Tap to flip, then mark Knew It or Still Learning โ missed cards come back until you master them.
Read the first 7 Threat Evaluation & Risk Analysis flashcards as text
A casino surveillance director notices a player consistently wins at blackjack over multiple visits using the same seating position. Which threat evaluation step should be taken first?
Answer: Conduct a pattern analysis review of recorded play sessions
Pattern analysis of recorded sessions is the evidence-gathering step required before any enforcement or escalation action.
Which quantitative method assigns numerical probabilities to threat scenarios based on historical incident data?
Answer: Actuarial risk modeling
Actuarial risk modeling uses statistical historical data to assign numerical probabilities and expected losses to specific threat scenarios.
A retailer's risk analysis shows shoplifting losses are highest on Sunday afternoons. This finding is best described as identifying a:
Answer: Temporal vulnerability window
A temporal vulnerability window is a specific time period during which risk is elevated, making it a key finding for targeted countermeasure deployment.
During a threat briefing, an analyst presents a scenario where a former employee with access credentials may attempt sabotage. This is an example of which threat category?
Answer: Insider threat with residual access
A former employee retaining active credentials represents an insider threat with residual access, combining insider knowledge with ongoing unauthorized access capability.
The criticality component in a risk formula primarily measures:
Answer: The value and importance of an asset to operations
Criticality measures how essential an asset is to operations, reflecting the magnitude of impact if that asset is compromised or destroyed.
A surveillance team identifies an individual conducting pre-operational surveillance of a facility's entry points over three days. This behavior is best classified as:
Answer: Indicator of a planning phase threat
Systematic observation of entry points over multiple days is a classic pre-attack planning indicator that warrants immediate escalation and active monitoring.
Which risk analysis framework specifically uses red team/blue team exercises to evaluate physical security vulnerabilities?
Answer: Adversarial simulation assessment
Adversarial simulation assessments use red team (attacker) and blue team (defender) roles to realistically test and evaluate physical security countermeasures under realistic attack conditions.