SSCP · Question #435
What is called the probability that a threat to an information system will materialize?
The correct answer is B. Risk. Risk is the probability (likelihood) that a threat will exploit a vulnerability and cause harm, combined with the potential impact of that harm. More specifically, this question focuses on the likelihood component: the chance that a threat actually materializes. A threat (A) is…
Question
Options
- AThreat
- BRisk
- CVulnerability
- DHole
How the community answered
(24 responses)- B88% (21)
- C4% (1)
- D8% (2)
Explanation
Risk is the probability (likelihood) that a threat will exploit a vulnerability and cause harm, combined with the potential impact of that harm. More specifically, this question focuses on the likelihood component: the chance that a threat actually materializes. A threat (A) is merely the potential agent or event (e.g., a hacker, a flood) - it does not itself describe probability. A vulnerability (C) is the weakness that could be exploited. 'Hole' (D) is informal slang for a vulnerability, not a formal security term. The formal definition of risk ties together threat, vulnerability, likelihood, and impact.
Topics
Community Discussion
No community discussion yet for this question.