CGRC · Question #285
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Response:
The correct answer is A. Vulnerability. A weakness in an information system, security procedure, or control that a threat can exploit is defined as a vulnerability.
Question
Weakness in an information system, system security procedures, internal controls, or implementation that could be exploited or triggered by a threat source. Response:
Options
- AVulnerability
- BAvailability
- CIntegrity
- DConfidentiality
How the community answered
(47 responses)- A87% (41)
- B4% (2)
- C6% (3)
- D2% (1)
Why each option
A weakness in an information system, security procedure, or control that a threat can exploit is defined as a vulnerability.
A vulnerability is a flaw or weakness in a system's design, implementation, operation, or management that can be exploited by a threat to compromise security. This definition directly matches the description provided in the question.
Availability is a security objective ensuring authorized users have timely and uninterrupted access to information and systems, not a weakness.
Integrity is a security objective ensuring information is protected from unauthorized modification or destruction, not a weakness.
Confidentiality is a security objective ensuring information is protected from unauthorized disclosure, not a weakness.
Concept tested: Vulnerability definition
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf
Topics
Community Discussion
No community discussion yet for this question.