nerdexam
(ISC)2

CGRC · Question #293

Anything that can exploit a vulnerability, intentionally or accidentally, and obtain, damage, or destroy an asset best describes Response:

The correct answer is D. Threat. The description directly defines a threat as an entity or event capable of exploiting a vulnerability to cause harm to an asset.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Anything that can exploit a vulnerability, intentionally or accidentally, and obtain, damage, or destroy an asset best describes Response:

Options

  • ARisk
  • BImpact
  • CVulnerability
  • DThreat

How the community answered

(35 responses)
  • A
    6% (2)
  • B
    3% (1)
  • D
    91% (32)

Why each option

The description directly defines a threat as an entity or event capable of exploiting a vulnerability to cause harm to an asset.

ARisk

Risk is the potential for loss or damage resulting from a threat exploiting a vulnerability, not the entity that exploits it.

BImpact

Impact refers to the magnitude of harm or loss that can be caused by a security event, not the source of the event itself.

CVulnerability

A vulnerability is a weakness or flaw in a system that can be exploited, not the entity that performs the exploitation.

DThreatCorrect

A threat is any potential danger that can exploit a vulnerability, intentionally or accidentally, to adversely affect an asset. This includes malicious actors, natural disasters, or human errors that could lead to unauthorized access, damage, or destruction of information system assets.

Concept tested: Core security concepts - threat

Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-30r1.pdf

Topics

#Threat#Vulnerability#Risk Management#Security Concepts

Community Discussion

No community discussion yet for this question.

Full CGRC Practice