nerdexam
(ISC)2

SSCP · Question #960

Which of the following is not a component of a Operations Security "triples"?

The correct answer is D. Risk. In Operations Security (OPSEC), the core analytic framework uses a conceptual 'triple' consisting of three elements: Asset (what you are trying to protect), Threat (who or what could harm the asset), and Vulnerability (a weakness that a threat could exploit). Risk is a derived…

Submitted by ricky.ec· Apr 18, 2026Risk Identification, Monitoring and Analysis

Question

Which of the following is not a component of a Operations Security "triples"?

Options

  • AAsset
  • BThreat
  • CVulnerability
  • DRisk

How the community answered

(35 responses)
  • A
    3% (1)
  • B
    3% (1)
  • C
    9% (3)
  • D
    86% (30)

Explanation

In Operations Security (OPSEC), the core analytic framework uses a conceptual 'triple' consisting of three elements: Asset (what you are trying to protect), Threat (who or what could harm the asset), and Vulnerability (a weakness that a threat could exploit). Risk is a derived concept - it is the result of combining threat, vulnerability, and asset value - not a standalone component of the triple itself. Because Risk is a calculated outcome rather than a foundational triple element, it is the correct answer here.

Topics

#Operations Security#Risk Management#Asset Threat Vulnerability#Security Concepts

Community Discussion

No community discussion yet for this question.

Full SSCP Practice