โ† All CSS Flashcard Decks

Risk Evaluation & Threat Analysis Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning โ€” missed cards come back until you master them.

Read the first 7 Risk Evaluation & Threat Analysis flashcards as text
  1. Which of the following best describes the concept of 'residual risk' in security management?

    Answer: The risk remaining after countermeasures have been implemented

    Residual risk is the level of risk that remains after security controls and countermeasures have been put in place.

  2. A security supervisor is asked to perform a Business Impact Analysis (BIA). What is the PRIMARY purpose of this assessment?

    Answer: Determine how security incidents would affect critical business operations

    A Business Impact Analysis identifies the effects that security incidents or disruptions would have on critical business functions and operations.

  3. In a threat analysis, 'frequency of occurrence' refers to:

    Answer: The likelihood that a specific threat will materialize within a given period

    Frequency of occurrence measures the probability or rate at which a particular threat event is expected to happen over a defined time period.

  4. A CSS candidate is reviewing a threat environment for a hospital. Which of the following would be classified as a natural hazard threat?

    Answer: A tornado damaging the facility

    Natural hazards are threats arising from natural phenomena such as tornadoes, earthquakes, floods, and severe weather.

  5. When conducting target hardening as part of a risk mitigation strategy, a security supervisor is primarily attempting to:

    Answer: Reduce vulnerabilities to make the target less attractive to offenders

    Target hardening involves implementing physical and procedural measures to reduce vulnerabilities and deter potential offenders.

  6. A supervisor uses crime statistics, incident reports, and police data to assess the threat environment. This process is known as:

    Answer: Threat assessment

    Threat assessment involves collecting and analyzing data about potential threats, including historical crime data and incident reports, to understand the threat environment.

  7. Which of the following is an example of risk transference?

    Answer: Purchasing insurance to cover potential losses from security incidents

    Risk transference shifts the financial burden of a potential loss to another party, most commonly through insurance policies.