ISP Security Risk Management 3 — Questions and Answers
Question 1: Which component of the risk equation directly measures the probability that a specific threat will materialize within a defined time period?
- Asset value
- Threat likelihood (Correct answer)
- Vulnerability rating
- Impact severity
Correct answer: Threat likelihood
Threat likelihood (or probability) quantifies how often or how probably a specific threat event will occur within a given timeframe.
Question 2: An ISP candidate is conducting a Business Impact Analysis (BIA). The PRIMARY purpose of this analysis is to:
- Identify all potential threat actors targeting the facility
- Determine the financial and operational consequences of disruptions to critical functions (Correct answer)
- Rank physical security countermeasures by cost
- Establish the chain of command during an emergency
Correct answer: Determine the financial and operational consequences of disruptions to critical functions
A BIA identifies critical business functions and quantifies the impact their disruption would have on the organization's operations and finances.
Question 3: In risk management, the 'single loss expectancy' (SLE) is calculated by multiplying:
- Asset value by annualized rate of occurrence
- Asset value by exposure factor (Correct answer)
- Threat likelihood by countermeasure cost
- Exposure factor by annualized rate of occurrence
Correct answer: Asset value by exposure factor
SLE = Asset Value × Exposure Factor, representing the expected monetary loss from a single occurrence of a specific threat.
Question 4: Which type of security assessment involves an independent reviewer examining policies, procedures, and controls without physically testing them?
- Penetration test
- Red team exercise
- Security audit (Correct answer)
- Vulnerability scan
Correct answer: Security audit
A security audit is a systematic review of documentation, policies, and controls to verify compliance and adequacy without active exploitation attempts.
Question 5: The CARVER matrix used in target vulnerability assessments evaluates targets across six criteria. Which of the following is NOT one of the CARVER criteria?
- Criticality
- Accessibility
- Redundancy (Correct answer)
- Effect
Correct answer: Redundancy
CARVER stands for Criticality, Accessibility, Recuperability, Vulnerability, Effect, and Recognizability — Redundancy is not one of the six criteria.
Question 6: During a security risk assessment of a chemical storage facility, the assessor identifies that a fence line runs only 10 feet from a critical valve manifold. This finding primarily represents a concern about which risk element?
- Threat probability
- Asset criticality
- Standoff distance and vulnerability (Correct answer)
- Regulatory compliance
Correct answer: Standoff distance and vulnerability
Insufficient standoff distance between a perimeter barrier and a critical asset increases vulnerability by reducing response time and blast/intrusion buffer.
Question 7: Which risk management standard published by ASIS International provides comprehensive guidance specifically for organizational resilience and security management?
- ASIS SPC.1-2009 (Correct answer)
- ISO 27001
- NFPA 730
- DHS CFATS
Correct answer: ASIS SPC.1-2009
ASIS SPC.1-2009 (Organizational Resilience Standard) provides a framework for security, preparedness, and continuity management aligned with ASIS professional practice.
Which component of the risk equation directly measures the probability that a specific threat will materialize within a defined time period?