nerdexam
(ISC)2

SSCP · Question #434

A weakness or lack of a safeguard, which may be exploited by a threat, causing harm to the information systems or networks is called a?

The correct answer is A. Vulnerability. A vulnerability is defined as a weakness, flaw, or absence of a security control that could be exploited by a threat agent to compromise a system. Classic examples include unpatched software, misconfigured firewalls, or weak passwords. A threat (C) is the potential event or…

Submitted by javi_es· Apr 18, 2026Security Concepts and Practices

Question

A weakness or lack of a safeguard, which may be exploited by a threat, causing harm to the information systems or networks is called a?

Options

  • AVulnerability
  • BRisk
  • CThreat
  • DOverflow

How the community answered

(23 responses)
  • A
    87% (20)
  • C
    4% (1)
  • D
    9% (2)

Explanation

A vulnerability is defined as a weakness, flaw, or absence of a security control that could be exploited by a threat agent to compromise a system. Classic examples include unpatched software, misconfigured firewalls, or weak passwords. A threat (C) is the potential event or actor that could exploit a vulnerability. Risk (B) is the probability and impact that a threat will actually exploit a vulnerability. 'Overflow' (D) is a specific type of vulnerability (e.g., buffer overflow), not the general term for the concept being described.

Topics

#Vulnerability#Security definitions#Information security concepts

Community Discussion

No community discussion yet for this question.

Full SSCP Practice