SSCP · Question #434
A weakness or lack of a safeguard, which may be exploited by a threat, causing harm to the information systems or networks is called a?
The correct answer is A. Vulnerability. A vulnerability is defined as a weakness, flaw, or absence of a security control that could be exploited by a threat agent to compromise a system. Classic examples include unpatched software, misconfigured firewalls, or weak passwords. A threat (C) is the potential event or…
Question
Options
- AVulnerability
- BRisk
- CThreat
- DOverflow
How the community answered
(23 responses)- A87% (20)
- C4% (1)
- D9% (2)
Explanation
A vulnerability is defined as a weakness, flaw, or absence of a security control that could be exploited by a threat agent to compromise a system. Classic examples include unpatched software, misconfigured firewalls, or weak passwords. A threat (C) is the potential event or actor that could exploit a vulnerability. Risk (B) is the probability and impact that a threat will actually exploit a vulnerability. 'Overflow' (D) is a specific type of vulnerability (e.g., buffer overflow), not the general term for the concept being described.
Topics
Community Discussion
No community discussion yet for this question.