nerdexam
EC-Council

112-52 · Question #165

What best defines risk in the context of information security?

The correct answer is A. The potential that a threat will exploit a vulnerability. Risk in information security is defined as the potential for a threat to exploit a vulnerability, causing harm to an asset - option A captures this precisely, reflecting the standard definition used across frameworks like NIST and ISO 27001. Options B, C, and D describe unrelated

Ethical Hacking Fundamentals

Question

What best defines risk in the context of information security?

Options

  • AThe potential that a threat will exploit a vulnerability
  • BA method of safeguarding against script kiddies
  • CThe process of transferring data over the internet
  • DThe implementation of a firewall

How the community answered

(55 responses)
  • A
    91% (50)
  • B
    5% (3)
  • C
    2% (1)
  • D
    2% (1)

Explanation

Risk in information security is defined as the potential for a threat to exploit a vulnerability, causing harm to an asset - option A captures this precisely, reflecting the standard definition used across frameworks like NIST and ISO 27001.

Options B, C, and D describe unrelated concepts: B conflates risk with a specific attacker type (script kiddies), C describes data transmission (a network concept, not a risk definition), and D describes a security control - which is actually a response to risk, not risk itself.

Memory tip: Think of the formula Risk = Threat × Vulnerability. If either is zero, risk is zero. This triangle helps anchor the definition: risk is always about the intersection of a threat and a weakness, not the tools or processes around them.

Topics

#Risk Definition#Threat#Vulnerability#Risk Management

Community Discussion

5
Lena V.Lena V.Nov 26, 2025

A is correct. Risk in infosec is defined as the likelihood that a threat will exploit an existing vulnerability, resulting in harm to an asset, and that core definition shows up constantly across frameworks like NIST and ISO 27001 so lock it in now.

15
Marisol A.Marisol A.Nov 19, 2025

A is the right call here. Risk in infosec is classically defined as the likelihood that a threat source will exercise a particular vulnerability, combined with the resulting impact to the organization. NIST SP 800-30 spells this out plainly, and the CHFI material leans on that same foundation. I will say the phrasing "potential that a threat will exploit a vulnerability" is slightly loose because it omits the impact component, but among these options it is the only one that even gestures at the actual definition. B, C, and D are not even in the same conversation as a definition of risk, so there is nothing tempting to chase there.

5
Orla P.Orla P.Dec 5, 2025

The classic definition question, and A is the one you want here. Risk in infosec is that combination of threat, vulnerability, and the likelihood that the two actually meet, so "the potential that a threat will exploit a vulnerability" captures that relationship cleanly. I know some study guides split hairs and define risk as "impact times likelihood" or fold in asset value, but for the purposes of this exam they want you thinking in threat-plus-vulnerability terms, and A delivers that. D is a control, B is barely a concept at all, and C is just network communication, so none of the distractors are even close to being tempting if you slow down for five seconds and read them.

5
Lena V.Lena V.Dec 5, 2025

The "impact times likelihood" framing does show up on some CISSP objectives so worth having in your back pocket even if A is the clean answer for this one.

0
Nina C.Nina C.Dec 14, 2025

So if I'm reading this right, risk is basically that in-between space where a threat and a vulnerability overlap, like the danger only exists if something can actually take advantage of a weakness, is that the core idea the exam is testing here?

3
Full 112-52 Practice