TPS Threat Assessment & Risk Analysis 3 — Questions and Answers
Question 1: Under Texas Occupations Code Chapter 1702, private security personnel conducting threat assessments must operate under the license of a:
- Local law enforcement agency
- Licensed investigations company or security services contractor (Correct answer)
- Federal government agency
- Private attorney
Correct answer: Licensed investigations company or security services contractor
Texas Occupations Code Chapter 1702 requires threat assessment activities to be conducted under the authority of a properly licensed security services contractor or investigations company.
Question 2: Which of the following BEST describes the concept of 'threat convergence' in risk analysis?
- Two security guards arriving at a post simultaneously
- Multiple independent threats aligning to create a compounded risk (Correct answer)
- A single threat affecting multiple locations at once
- Combining physical and cyber security into one department
Correct answer: Multiple independent threats aligning to create a compounded risk
Threat convergence occurs when multiple independent threat vectors align simultaneously, creating a compounded and often more severe overall risk than any single threat would pose.
Question 3: A security officer is asked to assess the 'criticality' of assets at a client site. Criticality primarily refers to:
- How expensive the asset is to replace
- How essential the asset is to the mission or operations of the organization (Correct answer)
- How visible the asset is to the public
- How old the asset is
Correct answer: How essential the asset is to the mission or operations of the organization
Criticality measures how essential an asset is to the core mission or operations of the organization, not just its monetary replacement cost.
Question 4: When documenting a threat assessment, the section describing the 'adversary capability' should include:
- A list of all employees at the facility
- The tools, skills, and resources available to potential threat actors (Correct answer)
- The security budget for the next fiscal year
- Maintenance schedules for security equipment
Correct answer: The tools, skills, and resources available to potential threat actors
Adversary capability documentation covers what tools, technical skills, financial resources, and organizational support a potential threat actor possesses.
Question 5: What is 'target hardening' in the context of risk mitigation?
- Training security staff to be more aggressive
- Implementing physical and procedural measures to make a target less attractive or accessible to attackers (Correct answer)
- Increasing insurance coverage on valuable assets
- Installing harder building materials
Correct answer: Implementing physical and procedural measures to make a target less attractive or accessible to attackers
Target hardening refers to implementing physical barriers, access controls, and procedural changes that make a potential target more difficult, costly, or risky for an adversary to attack.
Question 6: In threat assessment methodology, a 'credible threat' is one that:
- Has been reported to police at least once
- Has both the intent and capability to cause harm (Correct answer)
- Involves a weapon of any kind
- Has been made in writing
Correct answer: Has both the intent and capability to cause harm
A credible threat requires demonstration of both intent (desire to cause harm) AND capability (means to carry it out) — either alone is insufficient to classify a threat as fully credible.
Question 7: Which approach to risk management involves accepting a known risk because the cost of mitigation exceeds the potential loss?
- Risk transfer
- Risk avoidance
- Risk acceptance (Correct answer)
- Risk elimination
Correct answer: Risk acceptance
Risk acceptance is the deliberate decision to acknowledge and accept a known risk when the cost or burden of mitigation is greater than the potential harm the risk represents.
Under Texas Occupations Code Chapter 1702, private security personnel conducting threat assessments must operate under the license of a: