Courseiva
Security Concepts →hardMultiple Select

200-201 Security Concepts Practice Question

A security analyst is reviewing a recent security incident where an attacker gained unauthorized access to a server. The analyst needs to determine which factors contributed to the incident by examining the vulnerability, threat, and risk. Which TWO of the following best describe the relationship between these concepts in this scenario? (Choose two.)

⚠ Common exam trap

The trap here is equating risk with vulnerability or assuming all threats are human attackers, which oversimplifies the risk formula and ignores natural or accidental threats.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A vulnerability is a weakness in the server's software that the attacker exploited.

A vulnerability is a weakness that can be exploited, and a threat is the potential cause that exploits it. Together, they create risk, which is the potential for loss. The correct options define vulnerability and threat accurately in the context of the incident, while the others either misdefine terms or are too narrow.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Risk is the same as vulnerability and can be used interchangeably.

    Why it's wrong here

    Risk is the combination of the probability of an event and its consequences, not synonymous with vulnerability. Vulnerability is a weakness, while risk considers the likelihood and impact of that weakness being exploited. Using them interchangeably is incorrect and can lead to flawed risk assessments.

  • ✓

    A vulnerability is a weakness in the server's software that the attacker exploited.

    Why this is correct

    A vulnerability is a flaw or weakness in a system that can be exploited to violate security. In this scenario, the attacker gained access by exploiting a weakness, such as an unpatched service or misconfiguration. This definition correctly describes the role of a vulnerability in the incident.

  • ✗

    Risk is the potential for loss or damage when a threat exploits a vulnerability.

    Why it's wrong here

    While this definition of risk is generally accurate, the question asks for the relationship between vulnerability, threat, and risk in the context of the incident. This option describes risk itself, but it does not directly address how the concepts interrelate as well as the other options. It is a valid definition but not the best fit for the specific relationship asked.

  • ✓

    A threat is the potential cause of an incident that exploits a vulnerability.

    Why this is correct

    A threat is any circumstance or event with the potential to cause harm by exploiting a vulnerability. The attacker in this scenario represents the threat that acted upon the vulnerability. This option accurately describes the relationship between threat and vulnerability.

  • ✗

    A threat is always a deliberate attack by a human actor.

    Why it's wrong here

    Threats can be natural disasters, accidents, or non-malicious events, not only deliberate human attacks. In this scenario, the threat is the attacker, but defining threat as always deliberate is too narrow. This misconception can lead to overlooking other threat sources in risk analysis.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.