← All CSS Flashcard Decks

Risk Evaluation & Threat Analysis Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Evaluation & Threat Analysis flashcards as text
  1. During a risk evaluation, a supervisor identifies a threat but determines that the cost of the countermeasure exceeds the value of the asset at risk. The MOST appropriate risk response is to:

    Answer: Accept the risk and document the decision

    When countermeasure costs exceed asset value, risk acceptance is the rational response — the organization acknowledges and documents the risk without further action.

  2. A security supervisor notes that a warehouse has one unsecured loading dock that receives deliveries after hours. In a risk matrix, this scenario would be evaluated by examining both the likelihood of an incident and its:

    Answer: Potential consequence or severity

    Risk matrices evaluate scenarios using two axes: the probability/likelihood of an event occurring and the severity or consequence if it does occur.

  3. Which of the following is the BEST example of a proactive threat mitigation strategy?

    Answer: Installing motion-activated lighting before any incidents are reported

    Proactive strategies address vulnerabilities and deter threats before incidents occur, rather than responding after the fact.

  4. A security supervisor is tasked with analyzing the risk of workplace violence. Which indicator would MOST warrant escalation to a formal threat assessment?

    Answer: An employee making specific threats against a named coworker

    Specific, targeted threats against identifiable individuals are high-priority indicators that require immediate formal threat assessment and intervention.

  5. In the context of threat analysis, a 'threat actor' is best defined as:

    Answer: Any individual or group with the intent and capability to cause harm

    A threat actor is any person, group, or entity that has both the motivation and the capability to exploit vulnerabilities and cause harm.

  6. Annual Loss Expectancy (ALE) is calculated using which two components?

    Answer: Single loss expectancy and annualized rate of occurrence

    ALE is calculated by multiplying Single Loss Expectancy (SLE) by the Annualized Rate of Occurrence (ARO) to estimate yearly losses from a specific risk.

  7. A security supervisor reviews a facility and finds that an adversary would need to breach three independent layers of security to access the most sensitive area. This design principle is known as:

    Answer: Defense in depth

    Defense in depth is a layered security strategy that requires an adversary to defeat multiple independent security measures to reach a target.