CSPM Security Industry-Specific Knowledge 5 â Questions and Answers
Question 1: Which federal act requires federal contractors and subcontractors to report cyber incidents involving covered defense information (CDI) to the DoD within 72 hours?
- FISMA
- DFARS 252.204-7012 (Correct answer)
- NIST SP 800-171
- FAR 52.204-21
Correct answer: DFARS 252.204-7012
DFARS clause 252.204-7012 mandates that defense contractors report cybersecurity incidents involving covered defense information to DoD's DIBNet portal within 72 hours.
Question 2: In the context of hotel security management, which industry concept describes the legal duty a hotel owes to guests to provide reasonable protective measures against foreseeable criminal acts?
- Duty of Care
- Premises Liability under Innkeeper Law (Correct answer)
- Respondeat Superior
- Attractive Nuisance Doctrine
Correct answer: Premises Liability under Innkeeper Law
Premises liability under innkeeper law holds hotels to a heightened duty to protect guests from foreseeable criminal acts given the transient and vulnerable nature of hotel guests.
Question 3: A security project manager is implementing a CBRN detection system at a convention center. What does the 'N' in CBRN stand for?
- Neurological
- Nuclear (Correct answer)
- Non-conventional
- Nerve agent
Correct answer: Nuclear
CBRN stands for Chemical, Biological, Radiological, and Nuclearâthe four categories of weapons of mass destruction that emergency response and detection systems address.
Question 4: Under OSHA 29 CFR 1910.119, what type of security and safety management program is required for facilities that handle highly hazardous chemicals above threshold quantities?
- Integrated Safety Management System (ISMS)
- Process Safety Management (PSM) Program (Correct answer)
- Chemical Security Assessment (CSA)
- Hazardous Materials Emergency Response Plan
Correct answer: Process Safety Management (PSM) Program
OSHA's Process Safety Management (PSM) standard requires a comprehensive programâincluding hazard analysis, operating procedures, and incident investigationâfor facilities with threshold quantities of highly hazardous chemicals.
Question 5: When securing a healthcare facility's emergency department, which type of security assessment tool evaluates patient, staff, and visitor flow to identify vulnerability chokepoints?
- Threat Vulnerability Assessment (TVA)
- Crime Prevention Through Environmental Design (CPTED) Review (Correct answer)
- Healthcare Security Risk Score (HSRS)
- Joint Commission Environment of Care Survey
Correct answer: Crime Prevention Through Environmental Design (CPTED) Review
A CPTED review analyzes how the physical environmentâincluding layout, sight lines, and access flowâcan be designed or modified to reduce criminal opportunity and vulnerability.
Question 6: Which US statute specifically establishes criminal penalties for individuals who knowingly possess or transfer firearms in a school zone without authorization, affecting security project planning for K-12 facilities?
- Brady Handgun Violence Prevention Act
- Gun-Free School Zones Act (GFSZA) (Correct answer)
- Jeanne Clery Disclosure Act
- Safe Schools Act of 1994
Correct answer: Gun-Free School Zones Act (GFSZA)
The Gun-Free School Zones Act (18 U.S.C. § 922(q)) prohibits unauthorized possession of firearms within 1,000 feet of a school, directly affecting armed security deployment planning.
Question 7: A security manager at a pharmaceutical company must protect drug formulas as trade secrets. Which framework best guides the legal protections and security controls needed to maintain trade secret status under US law?
- Defend Trade Secrets Act (DTSA) + reasonable measures standard (Correct answer)
- HIPAA Security Rule administrative safeguards
- ISO 27001 Annex A controls
- NIST Cybersecurity Framework Protect function
Correct answer: Defend Trade Secrets Act (DTSA) + reasonable measures standard
The DTSA protects trade secrets when the owner takes 'reasonable measures' to keep them secret; the security program must demonstrably meet this standard to retain legal protection.
Which federal act requires federal contractors and subcontractors to report cyber incidents involving covered defense information (CDI) to the DoD within 72 hours?