nerdexam
EC-Council

112-52 · Question #12

Which of the following best describes a vulnerability in the context of information security?

The correct answer is B. A weakness in a system that could be exploited. Option B is correct because a vulnerability is formally defined as a flaw, weakness, or gap in a system's design, implementation, or controls that an attacker could exploit to gain unauthorized access or cause harm - it's a potential exposure, not an active attack. Why the distra

Information Gathering and Vulnerability Analysis

Question

Which of the following best describes a vulnerability in the context of information security?

Options

  • AAn unauthorized attempt to access a system
  • BA weakness in a system that could be exploited
  • CA method for encrypting data
  • DA tool used to assess security posture

How the community answered

(27 responses)
  • A
    4% (1)
  • B
    89% (24)
  • D
    7% (2)

Explanation

Option B is correct because a vulnerability is formally defined as a flaw, weakness, or gap in a system's design, implementation, or controls that an attacker could exploit to gain unauthorized access or cause harm - it's a potential exposure, not an active attack.

Why the distractors are wrong:

  • A describes a threat or attack attempt - an active action by an actor, not a system weakness.
  • C describes cryptography - a security control, the opposite of a vulnerability.
  • D describes a security assessment tool (like a vulnerability scanner or penetration testing framework) - a defensive instrument, not a weakness itself.

Memory tip: Think of the classic security triad - Threat → Vulnerability → Risk. A vulnerability is the middle piece: it's the crack in the wall that a threat actor exploits to create risk. If there's no crack (vulnerability), the threat can't get through.

Topics

#vulnerability definition#risk assessment#threat vs vulnerability#security fundamentals

Community Discussion

No community discussion yet for this question.

Full 112-52 Practice