Courseiva
Security Concepts →easyMultiple Select

200-201 Security Concepts Practice Question

A security analyst is assessing the risks to a company's data. The analyst identifies a vulnerability in the web application that could allow SQL injection. Which TWO terms correctly describe the elements of this risk scenario? (Choose two.)

⚠ Common exam trap

The trap is swapping vulnerability and threat — candidates often call the flaw a 'threat' because it sounds dangerous, but the flaw is the weakness (vulnerability) and the attacker's potential action is the threat.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

The SQL injection flaw in the application is a vulnerability.

Option C is correct because a SQL injection flaw is a weakness in the web application's code that can be leveraged to compromise the system, which is the definition of a vulnerability. Option E is correct because the possibility of an attacker exploiting that flaw represents a potential danger or adversary action, which is the definition of a threat. Option A is incorrect because the flaw itself is a vulnerability, not a threat; a threat is the actor or event that could exploit it. Option B is incorrect because an exploit is the specific technique or code that takes advantage of the vulnerability, not the combination of vulnerability and threat. Option D is incorrect because the possibility of exploitation describes a threat, not a vulnerability, which is the actual weakness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    The SQL injection flaw in the application is a threat.

    Why it's wrong here

    A threat is an actor or event with the potential to cause harm, such as an attacker or malicious input, not the flaw itself. The SQL injection weakness is the vulnerability. This option swaps the two terms, so it mislabels the element in the scenario.

  • ✗

    The combination of the vulnerability and threat is the exploit.

    Why it's wrong here

    An exploit is the actual technique or code that leverages a vulnerability, not the pairing of vulnerability and threat. This option confuses the exploit with the risk itself. Naming the exploit correctly matters when the question asks which elements describe the scenario, and the vulnerability and threat are separate elements.

  • ✓

    The SQL injection flaw in the application is a vulnerability.

    Why this is correct

    A vulnerability is a weakness in a system or application that an attacker could exploit. The SQL injection flaw is precisely such a weakness in the web application, making it the vulnerability element of this risk scenario.

  • ✗

    The possibility of an attacker exploiting the SQL injection is a vulnerability.

    Why it's wrong here

    A vulnerability is a weakness in the application, such as the SQL injection flaw, not the possibility of exploitation. That possibility describes risk or likelihood. The option inverts the definitions, so it fails to identify the vulnerability element the question requires.

  • ✓

    The possibility of an attacker exploiting the SQL injection is a threat.

    Why this is correct

    A threat is any potential cause of harm, so the attacker's possible exploitation of the SQL injection flaw is the threat element. The vulnerability itself is the weakness; the threat is the actor or event that could trigger it, matching the scenario's risk breakdown.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.