nerdexam
(ISC)2

CERTIFIED-IN-CYBERSECURITY · Question #782

You are talking to a new manager of our helpdesk. You are explaining how we do risk analysis. They ask you: "How do you define a vulnerability?"

The correct answer is C. A weakness that can possibly be exploited. In risk analysis terminology: a Vulnerability is a weakness that can be exploited (option C); a Threat is a potential harmful incident (option D); Risk is the likelihood and impact of a threat exploiting a vulnerability; and Residual Risk is the risk remaining after…

Security Principles

Question

You are talking to a new manager of our helpdesk. You are explaining how we do risk analysis. They ask you: "How do you define a vulnerability?"

Options

  • AThe total risk after we have implemented our countermeasures.
  • BHow bad is it if we are compromised?
  • CA weakness that can possibly be exploited.
  • DA potential harmful incident.

How the community answered

(33 responses)
  • A
    3% (1)
  • B
    6% (2)
  • C
    91% (30)

Explanation

In risk analysis terminology: a Vulnerability is a weakness that can be exploited (option C); a Threat is a potential harmful incident (option D); Risk is the likelihood and impact of a threat exploiting a vulnerability; and Residual Risk is the risk remaining after countermeasures are applied (option A). Option B describes Impact. Keeping these definitions precise is critical because risk analysis formulas depend on these distinct concepts.

Topics

#Vulnerability Definition#Risk Analysis#Cybersecurity Concepts#Security Principles

Community Discussion

No community discussion yet for this question.

Full CERTIFIED-IN-CYBERSECURITY Practice