ATO LEVEL II ACTUAL SCRIPT WITH 100
PERCENT CORRECT ANSWERS
◉ One step in regressive analysis is reevaluating an asset's
vulnerabilities.
Answer: True
◉ The fifth and final step in the risk management process is to
determine countermeasure options. Which of the following is the
goal of this step?
Answer: To identify potential countermeasures for reducing an
asset's vulnerabilities and overall risk to the asset
◉ The criteria used to determine the level of vulnerability include
which of the following? (Select all that apply)
Answer: A.) Effectiveness of the countermeasures B.) Quality C.)
Quality
◉ After you've completed all other steps, what final chart would
you use to summarize and record your information in order to get
the total cost for all countermeasures?
Answer: Countermeasure Analysis Chart
◉ When performing a countermeasures cost benefit analysis,
which two of the following are good questions to ask?
,Answer: A.) To what degree does the option delay, deter, detect,
defend, or destroy? B.) How does the asset value compare to
proposed cost of protection?
◉ Criminal, terrorist, insider, and natural disasters are examples
of categories of ______.
Answer: Threats
◉ Persons, facilities, materials, information, and activities are
categories of ______.
Answer: Vulnerabilites
◉ The smaller the risk area shared by assets, threats, and
vulnerabilities, the higher the risk level.
Answer: False
◉ One way to describe asset value is:
Answer: What is the impact of an undesirable event?
◉ Risk management is defined as the process of selecting and
implementing ______ to achieve an acceptable level of risk at an
acceptable cost.
Answer: countermeasures
, ◉ When determining an adversary's history, the fact that the
adversary might attempt an attack at a foreseeable future event is
irrelevant.
Answer: False
◉ The time to implement and oversee the countermeasure, the
time to prepare for its implementation, and any time required for
follow-up and evaluation have no impact when determining the
cost of a countermeasure.
Answer: False
◉ Which of the following statements defines an adversary?
Answer: Any individual, group, organization, or government that
conducts activities, or has the intention and capability to conduct
activities detrimental to assets.
◉ What is the risk rating of an asset with an impact of 10, a threat
rating of .12 and a vulnerability rating of .40?
Answer: 48
◉ When determining an adversary's capability, which of the
following collection methods includes resources such as
newspapers, internet, magazines, and conventions, FOIA requests,
seminars, and exhibits?
Answer: OSINT
PERCENT CORRECT ANSWERS
◉ One step in regressive analysis is reevaluating an asset's
vulnerabilities.
Answer: True
◉ The fifth and final step in the risk management process is to
determine countermeasure options. Which of the following is the
goal of this step?
Answer: To identify potential countermeasures for reducing an
asset's vulnerabilities and overall risk to the asset
◉ The criteria used to determine the level of vulnerability include
which of the following? (Select all that apply)
Answer: A.) Effectiveness of the countermeasures B.) Quality C.)
Quality
◉ After you've completed all other steps, what final chart would
you use to summarize and record your information in order to get
the total cost for all countermeasures?
Answer: Countermeasure Analysis Chart
◉ When performing a countermeasures cost benefit analysis,
which two of the following are good questions to ask?
,Answer: A.) To what degree does the option delay, deter, detect,
defend, or destroy? B.) How does the asset value compare to
proposed cost of protection?
◉ Criminal, terrorist, insider, and natural disasters are examples
of categories of ______.
Answer: Threats
◉ Persons, facilities, materials, information, and activities are
categories of ______.
Answer: Vulnerabilites
◉ The smaller the risk area shared by assets, threats, and
vulnerabilities, the higher the risk level.
Answer: False
◉ One way to describe asset value is:
Answer: What is the impact of an undesirable event?
◉ Risk management is defined as the process of selecting and
implementing ______ to achieve an acceptable level of risk at an
acceptable cost.
Answer: countermeasures
, ◉ When determining an adversary's history, the fact that the
adversary might attempt an attack at a foreseeable future event is
irrelevant.
Answer: False
◉ The time to implement and oversee the countermeasure, the
time to prepare for its implementation, and any time required for
follow-up and evaluation have no impact when determining the
cost of a countermeasure.
Answer: False
◉ Which of the following statements defines an adversary?
Answer: Any individual, group, organization, or government that
conducts activities, or has the intention and capability to conduct
activities detrimental to assets.
◉ What is the risk rating of an asset with an impact of 10, a threat
rating of .12 and a vulnerability rating of .40?
Answer: 48
◉ When determining an adversary's capability, which of the
following collection methods includes resources such as
newspapers, internet, magazines, and conventions, FOIA requests,
seminars, and exhibits?
Answer: OSINT