nerdexam
(ISC)2

SSCP · Question #413

Within the realm of IT security, which of the following combinations best defines risk?

The correct answer is B. Threat coupled with a vulnerability. In IT security, risk is formally defined as the likelihood that a threat will exploit a vulnerability, resulting in harm to an asset. The standard formula is: Risk = Threat × Vulnerability × Asset Value. A threat alone cannot cause harm if there is no vulnerability to exploit, an

Submitted by emma.c· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

Within the realm of IT security, which of the following combinations best defines risk?

Options

  • AThreat coupled with a breach
  • BThreat coupled with a vulnerability
  • CVulnerability coupled with an attack
  • DThreat coupled with a breach of security

How the community answered

(48 responses)
  • A
    6% (3)
  • B
    90% (43)
  • C
    2% (1)
  • D
    2% (1)

Explanation

In IT security, risk is formally defined as the likelihood that a threat will exploit a vulnerability, resulting in harm to an asset. The standard formula is: Risk = Threat × Vulnerability × Asset Value. A threat alone cannot cause harm if there is no vulnerability to exploit, and a vulnerability alone poses no risk if there is no threat to exploit it. Options A and D reference a 'breach,' which is an outcome of risk materializing - not the definition of risk itself. Option C ('vulnerability coupled with an attack') is closer but incorrect because an attack is an active event, whereas risk is a potential condition that exists before any attack occurs.

Topics

#Risk definition#Threat#Vulnerability#Security concepts

Community Discussion

No community discussion yet for this question.

Full SSCP Practice