wayground logo

Free Printable Worksheets

Font size

S
M
L
XL
Worksheets

Chapter 27: Security Risk Management

Total questions: 10

Worksheet time: 20mins

Name
Class
Date
1.

The terms “ threat ” and “ risk ” can be used interchangeably; for example, a “ threat assessment ” is the same as a “ risk assessment. ”

a)

True

b)

False

2.

The concept of “ risk management ” originated within the security profession.

a)

True

b)

False

3.

Because vulnerabilities are actually a characteristic of the organization or facility, they are:

a)

The risk factor over which the organization has the most control

b)

Impossible to accurately assess by an outside consultant

c)

The risk factor that is most expensive to correct

d)

The only risk factor that can be influenced by the organization

4.

According to “ Primer on Security Risk Management, ” the primary categories of threats are (choose all correct answers):

a)

Criminal

b)

Intentional

c)

Inadvertent

d)

Terrorist

e)

Natural

5.

In a scatter chart used for risk analysis, which quadrant represents a “ high-likelihood/ high-consequence ” risk?

a)

Quadrant 1

b)

Quadrant 2

c)

Quadrant 3

d)

Quadrant 4

6.

In order to effectively mitigate risks, a security professional should:

a)

Limit their strategy to using proven security measures only

b)

Assess all possible threats to the organization

c)

Apply a protection strategy that employs a suite of solutions

d)

Ensure that management is aware of existing vulnerabilities

7.

Buying insurance is one example of:

a)

Risk spreading

b)

Risk transfer

c)

Risk avoidance

d)

Risk reduction

8.

Which one of the following is not one of the underlying concepts on which a risk mitigation strategy should be based?

a)

The five avenues to address risk

b)

The “ Four D’s ”

c)

Layered security

d)

Quantitative analysis

9.

Risk management is a critical process that touches every aspect of organizational asset protection — and the activities of the professional protection officer.

a)

True

b)

False

10.

Service providers should not base their core business model on risk management principles.

a)

True

b)

False