PROTECTION PLAN EXAM
1. Which statement best describes the primary purpose of the
National Infrastructure Protection Plan?
A. To establish a single emergency response agency
B. To provide a national structure for critical infrastructure security and resilience
C. To replace every existing sector security program
D. To control privately owned infrastructure directly
Answer: B
Rationale: B is correct because NIPP provides a unifying structure for critical infrastructure security and
resilience efforts. A is incorrect because NIPP does not create one response agency. C is incorrect because
existing programs are integrated. D is incorrect because owners retain operational responsibility.
2. What does the NIPP recognize about the ownership of much of
the Nation's critical infrastructure?
A. Most infrastructure is exclusively federally owned
B. Infrastructure is primarily owned by State governments
C. Most infrastructure is privately owned and operated
D. Infrastructure ownership is limited to local governments
Answer: C
Rationale: C is correct because much U.S. critical infrastructure is privately owned and operated. A, B, and D
are incorrect because ownership is distributed among private entities and multiple levels of government
rather than concentrated within one governmental level.
3. Why is resilience considered an important component of critical
infrastructure protection?
A. It helps infrastructure withstand disruptions and recover effectively
B. It eliminates every possible infrastructure threat
C. It transfers infrastructure responsibility to Federal agencies
D. It prevents organizations from sharing operational information
1
,Answer: A
Rationale: A is correct because resilience involves the ability to withstand, adapt to, and recover from
disruptions. B is incorrect because no strategy eliminates every threat. C and D contradict the collaborative
approach emphasized by NIPP.
4. Which condition can create cascading consequences across
multiple critical infrastructure sectors?
A. A routine administrative meeting
B. A minor scheduling adjustment
C. A normal maintenance inspection
D. A disruption affecting an interdependent infrastructure system
Answer: D
Rationale: D is correct because interdependent systems can transmit disruptions across sectors. A, B, and C
generally do not create widespread cascading effects by themselves. NIPP emphasizes understanding
dependencies and interdependencies when managing infrastructure risk.
5. What does the term critical infrastructure generally identify
under the NIPP framework?
A. Assets used only by emergency responders
B. Systems and assets whose disruption could seriously affect national interests
C. Government buildings that have restricted entrances
D. Commercial facilities with large numbers of employees
Answer: B
Rationale: B is correct because critical infrastructure includes systems and assets whose incapacity or
destruction could have debilitating effects on security, economic security, public health, or safety. A, C, and
D are too narrow.
6. How does NIPP encourage government and private-sector
organizations to address infrastructure risk?
A. Through partnership, coordination, information sharing, and risk management
B. Through independent decisions without outside coordination
C. Through Federal ownership of private infrastructure
D. Through elimination of sector-specific responsibilities
2
,Answer: A
Rationale: A is correct because collaboration and coordinated risk management are central to NIPP. B
conflicts with the partnership model. C is not the purpose of NIPP. D is incorrect because sector
responsibilities remain important.
7. Which concept recognizes that infrastructure systems can
depend upon one another for successful operation?
A. Isolation
B. Redundancy
C. Interdependency
D. Privatization
Answer: C
Rationale: C is correct because interdependency describes relationships in which one infrastructure system
relies upon another. A suggests separation, B describes duplication or backup capacity, and D concerns
ownership rather than operational relationships.
8. Why should infrastructure owners consider both physical and
cyber risks when planning protection measures?
A. Cyber risks affect only Federal agencies
B. Physical risks have become irrelevant
C. Cybersecurity replaces physical security
D. Modern infrastructure frequently depends on connected information systems
Answer: D
Rationale: D is correct because increasing reliance on information and communications technology creates
cyber exposure alongside physical vulnerabilities. A, B, and C are incorrect because both physical and cyber
considerations remain important.
9. What is one major benefit of establishing trusted relationships
among critical infrastructure partners?
A. They eliminate the need for risk assessments
B. They support effective information sharing and coordinated action
C. They allow organizations to ignore legal requirements
D. They prevent private organizations from making independent decisions
3
, Answer: B
Rationale: B is correct because trusted partnerships facilitate appropriate information sharing and
coordinated risk management. A is incorrect because assessments remain necessary. C is incorrect because
legal protections still apply. D incorrectly suggests loss of organizational authority.
10. Which organization has a central Federal role in coordinating
national critical infrastructure security and resilience efforts?
A. Department of Homeland Security
B. Department of Agriculture alone
C. Department of Transportation alone
D. Department of Commerce alone
Answer: A
Rationale: A is correct because DHS has a major coordinating role in national critical infrastructure security
and resilience. The other departments may have sector responsibilities, but none alone performs the overall
coordinating role described by NIPP.
11. What is the primary focus of a risk-management approach to
critical infrastructure protection?
A. Eliminating all uncertainty before taking action
B. Protecting every asset identically
C. Understanding threats, vulnerabilities, consequences, and available options
D. Focusing exclusively on historical incidents
Answer: C
Rationale: C is correct because effective risk management considers threats, vulnerabilities, consequences,
and mitigation choices. A is unrealistic because uncertainty cannot be completely removed. B ignores
differing risk levels. D overlooks emerging conditions.
12. How can a community improve infrastructure resilience when
resources are limited?
A. By protecting only infrastructure owned by government
B. By avoiding partnerships with infrastructure owners
C. By treating every vulnerability as equally urgent
D. By prioritizing actions according to risk and consequences
4