CSP Threat Evaluation & Risk Analysis 2 — Questions and Answers
Question 1: A casino surveillance director notices a player consistently wins at blackjack over multiple visits using the same seating position. Which threat evaluation step should be taken first?
- Immediately ban the player from the property
- Conduct a pattern analysis review of recorded play sessions (Correct answer)
- Alert local law enforcement of suspected cheating
- Install additional cameras above that specific table
Correct answer: Conduct a pattern analysis review of recorded play sessions
Pattern analysis of recorded sessions is the evidence-gathering step required before any enforcement or escalation action.
Question 2: Which quantitative method assigns numerical probabilities to threat scenarios based on historical incident data?
- Delphi method
- Fault tree analysis
- Actuarial risk modeling (Correct answer)
- SWOT analysis
Correct answer: Actuarial risk modeling
Actuarial risk modeling uses statistical historical data to assign numerical probabilities and expected losses to specific threat scenarios.
Question 3: A retailer's risk analysis shows shoplifting losses are highest on Sunday afternoons. This finding is best described as identifying a:
- Threat actor profile
- Temporal vulnerability window (Correct answer)
- Risk tolerance threshold
- Countermeasure gap
Correct answer: Temporal vulnerability window
A temporal vulnerability window is a specific time period during which risk is elevated, making it a key finding for targeted countermeasure deployment.
Question 4: During a threat briefing, an analyst presents a scenario where a former employee with access credentials may attempt sabotage. This is an example of which threat category?
- External adversarial threat
- Insider threat with residual access (Correct answer)
- Environmental hazard
- Competitive intelligence threat
Correct answer: Insider threat with residual access
A former employee retaining active credentials represents an insider threat with residual access, combining insider knowledge with ongoing unauthorized access capability.
Question 5: The criticality component in a risk formula primarily measures:
- How likely a threat actor is to attempt an attack
- The value and importance of an asset to operations (Correct answer)
- The effectiveness of existing countermeasures
- The speed at which an incident can be detected
Correct answer: The value and importance of an asset to operations
Criticality measures how essential an asset is to operations, reflecting the magnitude of impact if that asset is compromised or destroyed.
Question 6: A surveillance team identifies an individual conducting pre-operational surveillance of a facility's entry points over three days. This behavior is best classified as:
- Random loitering requiring no action
- Indicator of a planning phase threat (Correct answer)
- Environmental reconnaissance by a competitor
- A false positive requiring dismissal
Correct answer: Indicator of a planning phase threat
Systematic observation of entry points over multiple days is a classic pre-attack planning indicator that warrants immediate escalation and active monitoring.
Question 7: Which risk analysis framework specifically uses red team/blue team exercises to evaluate physical security vulnerabilities?
- CARVER matrix
- Adversarial simulation assessment (Correct answer)
- FEMA THIRA
- ISO 31000
Correct answer: Adversarial simulation assessment
Adversarial simulation assessments use red team (attacker) and blue team (defender) roles to realistically test and evaluate physical security countermeasures under realistic attack conditions.
A casino surveillance director notices a player consistently wins at blackjack over multiple visits using the same seating position.
Which threat evaluation step should be taken first?