Security Program Integration Professional Certification (SPIPC)
EXAM WITH CORRECT ANSWER S
Question : What is the purpose of the asset assessment step of
the risk management process?
CORRECT ANSWER : • Identify assets requiring protection
and/or that are important to the organization and to national security • Identify undesirable events and expected impacts • Prioritize assets based on consequences of loss
Question : What is the purpose of the threat assessment step
of the risk management process?
CORRECT ANSWER : • Determine threats to identified
assets • Assess intent and capability of identified threats • Assess current threat level for the identified assets
Question : What is the purpose of the vulnerability assessment
step of the risk management process?
CORRECT ANSWER : • Identify existing countermeasures
and their level of effectiveness in reducing vulnerabilities • Identify potential vulnerabilities related to identified assets and their undesirable events • Identify current vulnerability level for the identified assets that can be exploited by the identified threats
Question : What is the purpose of the risk assessment step of
the risk management process?
CORRECT ANSWER : • Integrate information about the
impact of undesirable events (collected during the asset assessment step) and the likelihood of undesirable events (based on information collected during the threat and vulnerability assessment steps) to determine risks to identified assets
Question : What is the purpose of the countermeasure
determination step of the risk management process?
CORRECT ANSWER : • Identify potential countermeasures
to reduce vulnerability and/or threat and/or impact • Identify countermeasure benefits in terms of risk reduction
• Identify countermeasure costs • Conduct cost/benefit analysis • Prioritize options and prepare recommendation for decision maker
Question : What is the primary benefit of conducting the risk
management process?
CORRECT ANSWER : • National-level security policy
endorses a holistic risk management approach, allowing decision makers to effectively allocate resources that provide the necessary security to assets that match the threat to those assets
Question : What are the primary costs of conducting the risk
management process?
CORRECT ANSWER : • Time and effort necessary to
execute the five steps of the risk management process
Question : What are the potential challenges security
practitioners may face when enacting the risk management process?
CORRECT ANSW ER: • Availability of information
necessary to accurately determine the likelihood and impact of undesirable events
Question : Where can we get information to evaluate an
organization's compliance with security policies?
CORRECT ANSWER : • Self-inspections
Question : Where can we get information to evaluate the
effectiveness of an organization's security program?
CORRECT ANSWER : • Incident reports
• Regressive analysis • SME interviews (individuals involved in protecting Classified Military Information (CMI)) • Security planning documents • Surveys and audits • Information Systems (IS) Certification and Accreditation documentation • Facility certification and accreditation documentation