PROFESSIONAL CERTIFICATION RECENT UPLOADED
ACTUAL QUESTIONS & ANSWERS
SET OF 20 QUESTIONS
1. What is the purpose of the countermeasure determination step of the risk management process? -
ANSWER ✔ - • Identify potential countermeasures to reduce vulnerability and/or threat and/or
impact
• Identify countermeasure benefits in terms of risk reduction
• Identify countermeasure costs
• Conduct cost/benefit analysis
• Prioritize options and prepare recommendation for decision maker
2. What is the primary benefit of conducting the risk management process? - ANSWER ✔ - • National-
level security policy endorses a holistic risk management approach, allowing decision makers to
effectively allocate resources that provide the necessary security to assets that match the threat to
those assets
3. What are the primary costs of conducting the risk management process? - ANSWER ✔ - • Time and
effort necessary to execute the five steps of the risk management process
4. What are the potential challenges security practitioners may face when enacting the risk
management process? - ANSWER ✔ - • Availability of information necessary to accurately determine
the likelihood and impact of undesirable events
5. Where can we get information to evaluate an organization's compliance with security policies? -
ANSWER ✔ - • Self-inspections
Page 1 of 5
©™
, 6. Where can we get information to evaluate the effectiveness of an organization's security program? -
ANSWER ✔ - • Incident reports
• Regressive analysis
• SME interviews (individuals involved in protecting Classified Military Information (CMI))
• Security planning documents
• Surveys and audits
• Information Systems (IS) Certification and Accreditation documentation
• Facility certification and accreditation documentation
7. Given the incident, what is an example of an organization complying with security policy, but the
measure(s) it implemented appear to be ineffective? - ANSWER ✔ - • The appropriate signage and
notices are posted in appropriate areas, but are potentially ineffective considering a history of
uncleared personnel gaining access to restricted areas.
8. What is the purpose of the asset assessment step of the risk management process? - ANSWER ✔ - •
Identify assets requiring protection and/or that are important to the organization and to national
security
• Identify undesirable events and expected impacts
• Prioritize assets based on consequences of loss
9. What is the purpose of the threat assessment step of the risk management process? - ANSWER ✔ - •
Determine threats to identified assets
• Assess intent and capability of identified threats
• Assess current threat level for the identified assets
10. What is the purpose of the vulnerability assessment step of the risk management process? -
ANSWER ✔ - • Identify existing countermeasures and their level of effectiveness in reducing
vulnerabilities
• Identify potential vulnerabilities related to identified assets and their undesirable events
• Identify current vulnerability level for the identified assets that can be exploited by the
identified threats
11. What is the purpose of the risk assessment step of the risk management process? - ANSWER ✔ - •
Integrate information about the impact of undesirable events (collected during the asset assessment
Page 2 of 5
©™