1.  Detecting an infrastructure attack is a complex process; what kind of indicators or information would help you make the determination that a threat is underway? 

2.  What is the difference between front-loaded and back-loaded methods in the context of trigger intensity required to initiate a response process? 

Two pages each question with APA format and references