Courseiva
Security Concepts →easyMultiple Choice

200-201 Security Concepts Practice Question

A security administrator is reviewing the company's incident response plan and wants to ensure that the team understands the difference between a vulnerability, a threat, and a risk. During a tabletop exercise, the administrator presents a scenario: a web server has an unpatched Apache Struts vulnerability, and a known exploit exists publicly. Which term best describes the unpatched Apache Struts vulnerability in this context?

⚠ Common exam trap

The trap here is equating a vulnerability with an exploit because a public exploit exists; however, the exploit is the method used to take advantage of the weakness, while the vulnerability is the weakness itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability

The unpatched Apache Struts issue is a software flaw that can be leveraged by an attacker, making it a vulnerability. Understanding this distinction is crucial for risk assessment: vulnerabilities are weaknesses, threats are actors or events that can exploit them, and risk is the potential impact. Correctly identifying the vulnerability helps prioritize remediation such as patching.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Threat

    Why it's wrong here

    A threat is any potential danger that could exploit a vulnerability, such as an attacker or a malicious program. The unpatched software itself is not the threat; it is the weakness that a threat could exploit. Therefore, labeling the vulnerability as a threat misrepresents the risk terminology.

  • ✗

    Exploit

    Why it's wrong here

    An exploit is a piece of code or a technique that takes advantage of a vulnerability. While a known exploit exists for the Apache Struts flaw, the vulnerability itself is the underlying weakness. The exploit is the tool used to attack the vulnerability, not the vulnerability itself.

  • ✓

    Vulnerability

    Why this is correct

    A vulnerability is a weakness or flaw in a system that can be exploited by a threat. The unpatched Apache Struts vulnerability is a specific software weakness that could allow an attacker to compromise the server. This term accurately describes the condition of the unpatched software.

  • ✗

    Risk

    Why it's wrong here

    Risk is the potential for loss or damage when a threat exploits a vulnerability, often expressed as a combination of likelihood and impact. The unpatched Apache Struts flaw is a weakness, not the resulting risk. Calling it risk would confuse the cause with the potential outcome.

About these practice questions

Courseiva writes every 200-201 question from scratch — 968 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.