SECURITY THREAT AND RISK (STR) EXAMINATION
COMPLETE QUESTIONS AND DETAILED SOLUTIONS
LATEST UPDATE THIS YEAR JUST RELEASED
Coverage Areas (Short Summary)
1. Security Risk Management
o Risk identification, assessment methodologies, risk analysis, treatment options, and
continuous monitoring.
2. Threat Assessment
o Identifying internal and external threats including criminal activity, terrorism, cyber
threats, insider threats, and natural hazards.
3. Physical Security
o Security barriers, perimeter protection, access control systems, surveillance
technologies, locks, lighting, and intrusion detection.
4. Security Planning
o Developing security policies, emergency response plans, business continuity, and
security procedures.
5. Security Operations
o Incident management, patrol procedures, investigations, reporting, evidence
preservation, and daily operational security.
6. Information and Cyber Security Fundamentals
o Confidentiality, integrity, availability (CIA), access controls, cybersecurity threats, and
data protection principles.
7. Emergency Management
o Crisis response, evacuation procedures, disaster recovery, incident command systems,
and emergency communications.
8. Legal and Ethical Responsibilities
o Privacy laws, legal authority, use of force, professional ethics, compliance requirements,
and duty of care.
9. Security Technologies
o CCTV systems, alarm systems, biometrics, electronic access control, security software,
and integrated security management systems.
10. Communication and Incident Reporting
Effective communication, documentation, report writing, interviewing, stakeholder
coordination, and post-incident evaluation.
Security Threat and Risk (STR) Examination
,Question 1
Which step in the security risk management process should always occur before
selecting risk treatment strategies to ensure decisions are based on identified
vulnerabilities and credible threat information?
A. Implement security controls immediately
B. Conduct a comprehensive risk assessment
C. Purchase additional surveillance equipment
D. Review employee attendance records
Answer: B
Rationale: A comprehensive risk assessment identifies assets, threats,
vulnerabilities, and potential impacts before determining the most appropriate
mitigation strategies.
Question 2
A facility security manager discovers several unsecured entrances during an
inspection. Which action best reduces the immediate security risk while
maintaining normal business operations?
A. Ignore the issue until annual maintenance
B. Install temporary access controls and monitor entrances
C. Close the entire facility indefinitely
D. Remove existing security cameras
Answer: B
,Rationale: Temporary access controls combined with increased monitoring
immediately reduce unauthorized access while allowing operations to continue
safely.
Question 3
Which statement best describes the primary purpose of conducting a threat
assessment before implementing new organizational security measures?
A. To estimate future employee salaries
B. To identify credible threats that could exploit vulnerabilities
C. To replace all existing security personnel
D. To eliminate every possible organizational risk completely
Answer: B
Rationale: Threat assessments identify realistic threats capable of exploiting
vulnerabilities, allowing organizations to prioritize appropriate security controls.
Question 4
Which physical security measure is generally considered the first line of defense
against unauthorized entry into a secured facility?
A. Interior office locks
B. Perimeter fencing and controlled entry points
C. Employee identification badges only
D. Internal security audits
Answer: B
, Rationale: Perimeter security discourages, delays, and detects unauthorized
access before intruders reach sensitive areas.
Question 5
An organization identifies a high probability of unauthorized access to its data
center. Which risk treatment option most effectively reduces this identified
security risk?
A. Accept the risk without documentation
B. Install biometric access controls and surveillance
C. Remove all physical security measures
D. Publish access codes publicly
Answer: B
Rationale: Biometrics and surveillance significantly reduce unauthorized access by
strengthening authentication and providing continuous monitoring.
Question 6
Which principle requires security controls to provide protection proportional to
the value and criticality of the asset being protected?
A. Risk-based security
B. Opportunity management
C. Cost avoidance
D. Administrative convenience
Answer: A
COMPLETE QUESTIONS AND DETAILED SOLUTIONS
LATEST UPDATE THIS YEAR JUST RELEASED
Coverage Areas (Short Summary)
1. Security Risk Management
o Risk identification, assessment methodologies, risk analysis, treatment options, and
continuous monitoring.
2. Threat Assessment
o Identifying internal and external threats including criminal activity, terrorism, cyber
threats, insider threats, and natural hazards.
3. Physical Security
o Security barriers, perimeter protection, access control systems, surveillance
technologies, locks, lighting, and intrusion detection.
4. Security Planning
o Developing security policies, emergency response plans, business continuity, and
security procedures.
5. Security Operations
o Incident management, patrol procedures, investigations, reporting, evidence
preservation, and daily operational security.
6. Information and Cyber Security Fundamentals
o Confidentiality, integrity, availability (CIA), access controls, cybersecurity threats, and
data protection principles.
7. Emergency Management
o Crisis response, evacuation procedures, disaster recovery, incident command systems,
and emergency communications.
8. Legal and Ethical Responsibilities
o Privacy laws, legal authority, use of force, professional ethics, compliance requirements,
and duty of care.
9. Security Technologies
o CCTV systems, alarm systems, biometrics, electronic access control, security software,
and integrated security management systems.
10. Communication and Incident Reporting
Effective communication, documentation, report writing, interviewing, stakeholder
coordination, and post-incident evaluation.
Security Threat and Risk (STR) Examination
,Question 1
Which step in the security risk management process should always occur before
selecting risk treatment strategies to ensure decisions are based on identified
vulnerabilities and credible threat information?
A. Implement security controls immediately
B. Conduct a comprehensive risk assessment
C. Purchase additional surveillance equipment
D. Review employee attendance records
Answer: B
Rationale: A comprehensive risk assessment identifies assets, threats,
vulnerabilities, and potential impacts before determining the most appropriate
mitigation strategies.
Question 2
A facility security manager discovers several unsecured entrances during an
inspection. Which action best reduces the immediate security risk while
maintaining normal business operations?
A. Ignore the issue until annual maintenance
B. Install temporary access controls and monitor entrances
C. Close the entire facility indefinitely
D. Remove existing security cameras
Answer: B
,Rationale: Temporary access controls combined with increased monitoring
immediately reduce unauthorized access while allowing operations to continue
safely.
Question 3
Which statement best describes the primary purpose of conducting a threat
assessment before implementing new organizational security measures?
A. To estimate future employee salaries
B. To identify credible threats that could exploit vulnerabilities
C. To replace all existing security personnel
D. To eliminate every possible organizational risk completely
Answer: B
Rationale: Threat assessments identify realistic threats capable of exploiting
vulnerabilities, allowing organizations to prioritize appropriate security controls.
Question 4
Which physical security measure is generally considered the first line of defense
against unauthorized entry into a secured facility?
A. Interior office locks
B. Perimeter fencing and controlled entry points
C. Employee identification badges only
D. Internal security audits
Answer: B
, Rationale: Perimeter security discourages, delays, and detects unauthorized
access before intruders reach sensitive areas.
Question 5
An organization identifies a high probability of unauthorized access to its data
center. Which risk treatment option most effectively reduces this identified
security risk?
A. Accept the risk without documentation
B. Install biometric access controls and surveillance
C. Remove all physical security measures
D. Publish access codes publicly
Answer: B
Rationale: Biometrics and surveillance significantly reduce unauthorized access by
strengthening authentication and providing continuous monitoring.
Question 6
Which principle requires security controls to provide protection proportional to
the value and criticality of the asset being protected?
A. Risk-based security
B. Opportunity management
C. Cost avoidance
D. Administrative convenience
Answer: A