nerdexam
Isaca

CISM · Question #682

An information security manager has discovered a new technique that cybercriminals are exploiting. Which of the following has the manager identified?

The correct answer is D. A threat. In information security risk terminology, a threat is any potential cause of an unwanted incident - including the techniques, tools, or actors that could exploit a vulnerability. Discovering a new exploitation technique used by cybercriminals is identifying a threat. A risk (B)…

Submitted by thandi_sa· Apr 18, 2026Information Security Risk Management

Question

An information security manager has discovered a new technique that cybercriminals are exploiting. Which of the following has the manager identified?

Options

  • AAn event
  • BA risk
  • CAn incident
  • DA threat

How the community answered

(44 responses)
  • B
    5% (2)
  • C
    2% (1)
  • D
    93% (41)

Explanation

In information security risk terminology, a threat is any potential cause of an unwanted incident - including the techniques, tools, or actors that could exploit a vulnerability. Discovering a new exploitation technique used by cybercriminals is identifying a threat. A risk (B) is the combination of a threat, a vulnerability, and potential impact. An event (A) is an observed occurrence. An incident (C) is a confirmed event that has actually caused or is causing harm. Since no harm has occurred yet and this is a technique in the wild, it fits the definition of a threat.

Topics

#Threat identification#Security terminology#Risk management concepts

Community Discussion

No community discussion yet for this question.

Full CISM Practice