nerdexam
(ISC)2

CGRC · Question #285

Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Response:

The correct answer is A. Vulnerability. A weakness in an information system, security procedure, or control that a threat can exploit is defined as a vulnerability.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Response:

Options

  • AVulnerability
  • BAvailability
  • CIntegrity
  • DConfidentiality

How the community answered

(47 responses)
  • A
    87% (41)
  • B
    4% (2)
  • C
    6% (3)
  • D
    2% (1)

Why each option

A weakness in an information system, security procedure, or control that a threat can exploit is defined as a vulnerability.

AVulnerabilityCorrect

A vulnerability is a flaw or weakness in a system's design, implementation, operation, or management that can be exploited by a threat to compromise security. This definition directly matches the description provided in the question.

BAvailability

Availability is a security objective ensuring authorized users have timely and uninterrupted access to information and systems, not a weakness.

CIntegrity

Integrity is a security objective ensuring information is protected from unauthorized modification or destruction, not a weakness.

DConfidentiality

Confidentiality is a security objective ensuring information is protected from unauthorized disclosure, not a weakness.

Concept tested: Vulnerability definition

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Vulnerability Definition#Information Security Concepts#Risk Management Fundamentals#Threats and Vulnerabilities

Community Discussion

No community discussion yet for this question.

Full CGRC Practice