nerdexam
(ISC)2

CGRC · Question #63

Not all deficiencies in controls or lack of security protections are vulnerabilities. Vulnerabilities in control can be defined as: Response:

The correct answer is A. Only deficiencies that can be explioted. A vulnerability is specifically a deficiency in a control or lack of security protection that can be exploited by a threat to cause harm.

Security and Privacy Governance, Risk Management, and Compliance Program

Question

Not all deficiencies in controls or lack of security protections are vulnerabilities. Vulnerabilities in control can be defined as:

Response:

Options

  • AOnly deficiencies that can be explioted
  • BMissing patches
  • CAll deficiencies in the controls
  • DAcceptable risks to the organization

How the community answered

(66 responses)
  • A
    91% (60)
  • B
    2% (1)
  • C
    3% (2)
  • D
    5% (3)

Why each option

A vulnerability is specifically a deficiency in a control or lack of security protection that can be exploited by a threat to cause harm.

AOnly deficiencies that can be expliotedCorrect

A vulnerability is defined as a weakness in an information system, security procedures, internal controls, or implementation that could be exploited by a threat source. Simply having a deficiency is not enough; for it to be a vulnerability, it must present a potential pathway for exploitation.

BMissing patches

Missing patches are a type of vulnerability, but the definition of a vulnerability is broader than just missing patches.

CAll deficiencies in the controls

Not all deficiencies are vulnerabilities; a deficiency must be exploitable to be considered a vulnerability in the context of security.

DAcceptable risks to the organization

Acceptable risks are the risks an organization is willing to tolerate, which is a risk management decision, not a definition of a vulnerability itself.

Concept tested: Definition of vulnerability

Source: https://csrc.nist.gov/glossary/term/vulnerability

Topics

#Vulnerability definition#Control deficiencies#Risk management concepts

Community Discussion

No community discussion yet for this question.

Full CGRC Practice