← All CSS Flashcard Decks

Risk Evaluation & Threat Analysis Flashcards

7 cards from real CSS practice questions. Tap to flip, then mark Knew It or Still Learning — missed cards come back until you master them.

Read the first 7 Risk Evaluation & Threat Analysis flashcards as text
  1. A security supervisor is asked to distinguish between a 'hazard' and a 'threat' during a risk briefing. Which statement is MOST accurate?

    Answer: Threats involve human intent; hazards are conditions with potential to cause harm without intent

    A threat typically involves intentional human action, while a hazard is a condition — natural or accidental — that has the potential to cause harm without intent.

  2. Which of the following scenarios represents an 'opportunity-based' threat rather than a 'targeted' threat?

    Answer: A burglar who notices an unlocked door and spontaneously enters a facility

    Opportunity-based threats arise when an offender exploits an unplanned vulnerability they encounter, rather than conducting advance planning against a specific target.

  3. A CSS supervisor is updating a risk register. What information should a risk register primarily contain?

    Answer: Identified risks, their likelihood, impact, owner, and mitigation status

    A risk register is a documented record of identified risks, their assessed probability and impact, responsible owners, and the status of mitigation actions.

  4. During a threat analysis workshop, a supervisor asks participants to imagine ways an adversary could defeat current security measures. This brainstorming technique is called:

    Answer: Red team analysis

    Red team analysis involves thinking and acting like an adversary to identify weaknesses and gaps in existing security measures.

  5. A supervisor discovers that a data center has a single point of failure in its power supply. In a risk context, a single point of failure is a:

    Answer: Vulnerability that, if exploited, would cause total system failure

    A single point of failure is a critical vulnerability where failure of one component results in the failure of the entire system or operation.

  6. A security supervisor is evaluating the risk posed by civil unrest near a corporate office. Which factor would MOST influence the severity rating of this threat?

    Answer: The proximity of the unrest to the facility and the facility's profile as a potential target

    Severity is most influenced by how close the threat is to the asset and whether the asset is a plausible or symbolic target for those causing unrest.

  7. Which risk treatment option involves completely removing an activity or asset to eliminate the associated risk?

    Answer: Risk avoidance

    Risk avoidance eliminates risk entirely by discontinuing the activity, removing the asset, or changing the plan that creates the exposure.