Courseiva
Security Concepts →easyMultiple Choice

200-201 Security Concepts Practice Question

Which security concept describes the potential for a threat to exploit a vulnerability, and is often expressed as a combination of likelihood and impact?

⚠ Common exam trap

Many exam-takers confuse the four related terms — threat, vulnerability, exploit, and risk — because they are often used interchangeably in casual conversation, but the exam requires recognizing that only risk combines likelihood and impact.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Risk

Risk is defined as the potential for a threat to exploit a vulnerability, typically calculated as likelihood × impact. It is the overarching concept that combines the probability of a threat event with the resulting business or asset damage. In security frameworks like NIST and ISO 27005, risk = f(threat, vulnerability, impact, likelihood), which matches the question's wording exactly.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Risk

    Why this is correct

    Risk quantifies the potential for a threat to exploit a vulnerability, combining the likelihood of that exploitation with the resulting business impact. This matches the stem's definition precisely, distinguishing it from a vulnerability or threat in isolation.

  • ✗

    Exploit

    Why it's wrong here

    An exploit is the concrete technique or code that takes advantage of a weakness, not the likelihood-and-impact potential described. It is tempting because exploitation is the event risk quantifies, but exploit would be the correct answer to a question asking what actually leverages a vulnerability during an attack.

  • ✗

    Threat

    Why it's wrong here

    A threat is an actor or circumstance with the potential to cause harm, not the combined likelihood-and-impact measure the stem defines. Threat is tempting because it appears in the risk formula alongside vulnerability, but it would be correct for a question asking what exploits a weakness, not what quantifies exposure.

  • ✗

    Vulnerability

    Why it's wrong here

    Vulnerability is the weakness itself, a flaw or misconfiguration a threat could leverage; the stem instead defines risk, the likelihood-and-impact potential for exploitation. Vulnerability is tempting because it appears in the risk equation, but it would be the correct answer to a question asking what an exploit targets.

About these practice questions

This 200-201 question is part of Courseiva's 968-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official Cisco exam blueprint

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.