Question 1
In risk management, vulnerability is best described as:
Correct Answer:
Intrinsic properties that create susceptibility to risk
Explanation:
Vulnerability means inherent weaknesses that make an asset, system, or process susceptible to harm. It’s about the conditions inside the asset that allow threats to cause damage, not the threat itself or the protective measures. A vulnerability is what a threat can exploit—think of unpatched software, weak configurations, or gaps in procedures. When such weaknesses exist, the risk rises because a threat has a feasible path to cause impact. The other options describe things that aren’t vulnerabilities: an external threat is the attacker or event; a security control is a safeguard; a remediation action is how you fix the weakness.
Question 2
Which CRAVED attribute makes items attractive to thieves because they can be hidden?
Correct Answer:
Concealable
Explanation:
Concealable is the attribute that directly addresses hiding. When an item can be concealed, a thief can take it with a lower risk of being noticed, because it can be hidden in clothing, bags, or pockets and moved away discreetly. That ability to hide makes such items particularly attractive to thieves. The other CRAVED aspects influence theft in different ways—for example, removable means it’s easy to detach, available means it’s easy to access, valuable signals high reward, disposable means it can be disposed of after theft, and enjoyable to take relates to the thrill of stealing. None of these specifically describe the ease of hiding the item, which is why concealability best fits the question.
Question 3
Which term refers to actions taken to lessen the probability, negative consequences, or both associated with a risk?
Correct Answer:
Risk tolerance
Explanation:
Actions taken to lessen the probability or the consequences of a risk are called risk reduction. This involves implementing controls, safeguards, and countermeasures to lower how likely the risk is to occur or how severe its impact would be if it does occur. Examples include applying security patches, adding access controls, creating redundancy, backing up data, training staff, and establishing incident response plans. This differs from risk analysis, which is about identifying and evaluating risks; risk criteria, which are the standards used to judge risk levels; and risk tolerance, which is the amount of risk an organization is willing to accept.
Question 4
Which term relates to evaluating the consequences of a particular outcome?
Correct Answer:
Impact
Explanation:
Evaluating the consequences of a particular outcome centers on impact. Impact measures how severe the effects would be if an event occurs—such as financial losses, injuries, downtime, or damage to reputation. It’s the aspect that tells you how bad the result could be, which is why risk assessment often uses the formula Risk = Likelihood × Impact to prioritize protective measures. The other terms describe different ideas: likelihood is the probability that something will happen, an incident is the event itself, and integrity refers to the trustworthiness or accuracy of data and systems. So, the term that relates to evaluating consequences is impact.
Question 5
Risk treatment is NOT which of the following?
Correct Answer:
Ignoring the risk
Explanation:
Risk treatment involves actions to alter risk exposure—such as avoiding the activity, reducing the hazard, transferring the risk, or accepting the remaining risk with a plan. Ignoring the risk is not a treatment at all; it does nothing to reduce likelihood or impact and leaves the exposure unmanaged. The other options illustrate legitimate treatment approaches: avoiding the activity eliminates exposure; removing the risk source eliminates the hazard; and taking on more risk to pursue an opportunity represents a deliberate risk acceptance or appetite decision in pursuit of benefit. Therefore, ignoring the risk is not a risk treatment.
Question 1
Exam overview

About this Exam

Prepare with the ANSI ASIS PAP.1-2012 Physical Asset Protection APP Practice Exam practice quiz. This question bank includes 10 questions covering term, risk, describes, consequences, and associated. Use it to review important concepts, identify knowledge gaps, and build confidence for the related exam, course, or assessment.

More details

Additional Information

ANSI ASIS PAP.1-2012 Physical Asset Protection APP Practice Exam

This practice set contains 10 questions from the matching question bank and focuses on term, risk, describes, consequences, and associated. Work through each question carefully, review the provided solutions, and revisit topics that need more study before your next attempt.

This is an independent study resource intended for practice and review; it is not an official examination or an endorsement by any organization named in the title.

Quiz information

Frequently Asked Questions

The complete question count is available after full access is unlocked.
No fixed duration is currently configured for this quiz.
Question explanations are included where they are available in the quiz content, helping you review the reasoning after answering.
Yes. You can retake the practice test again as you continue studying during your available access period.
After your access is confirmed, you can continue into the complete practice exam from this quiz flow.
Unless explicitly stated otherwise, this page provides independent practice material for study and exam preparation and is not the official examination itself.
Keep studying

Related Questions