nerdexam
(ISC)2

SSCP · Question #435

What is called the probability that a threat to an information system will materialize?

The correct answer is B. Risk. Risk is the probability (likelihood) that a threat will exploit a vulnerability and cause harm, combined with the potential impact of that harm. More specifically, this question focuses on the likelihood component: the chance that a threat actually materializes. A threat (A) is…

Submitted by hans_de· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

What is called the probability that a threat to an information system will materialize?

Options

  • AThreat
  • BRisk
  • CVulnerability
  • DHole

How the community answered

(24 responses)
  • B
    88% (21)
  • C
    4% (1)
  • D
    8% (2)

Explanation

Risk is the probability (likelihood) that a threat will exploit a vulnerability and cause harm, combined with the potential impact of that harm. More specifically, this question focuses on the likelihood component: the chance that a threat actually materializes. A threat (A) is merely the potential agent or event (e.g., a hacker, a flood) - it does not itself describe probability. A vulnerability (C) is the weakness that could be exploited. 'Hole' (D) is informal slang for a vulnerability, not a formal security term. The formal definition of risk ties together threat, vulnerability, likelihood, and impact.

Topics

#Risk Management#Threats#Security Definitions#Probability

Community Discussion

No community discussion yet for this question.

Full SSCP Practice