CERTIFIED-IN-CYBERSECURITY · Question #782
You are talking to a new manager of our helpdesk. You are explaining how we do risk analysis. They ask you: "How do you define a vulnerability?"
The correct answer is C. A weakness that can possibly be exploited. In risk analysis terminology: a Vulnerability is a weakness that can be exploited (option C); a Threat is a potential harmful incident (option D); Risk is the likelihood and impact of a threat exploiting a vulnerability; and Residual Risk is the risk remaining after…
Question
You are talking to a new manager of our helpdesk. You are explaining how we do risk analysis. They ask you: "How do you define a vulnerability?"
Options
- AThe total risk after we have implemented our countermeasures.
- BHow bad is it if we are compromised?
- CA weakness that can possibly be exploited.
- DA potential harmful incident.
How the community answered
(33 responses)- A3% (1)
- B6% (2)
- C91% (30)
Explanation
In risk analysis terminology: a Vulnerability is a weakness that can be exploited (option C); a Threat is a potential harmful incident (option D); Risk is the likelihood and impact of a threat exploiting a vulnerability; and Residual Risk is the risk remaining after countermeasures are applied (option A). Option B describes Impact. Keeping these definitions precise is critical because risk analysis formulas depend on these distinct concepts.
Topics
Community Discussion
No community discussion yet for this question.