Courseiva
Security Concepts →easyMultiple Choice

200-201 Security Concepts Practice Question

Which term describes a weakness in a system that could be exploited by a threat?

⚠ Common exam trap

Cisco often tests the distinction between vulnerability and exploit by describing a scenario where a tool is used to break into a system, leading candidates to mistakenly select 'exploit' when the question asks for the weakness itself.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability

A vulnerability is a weakness in a system, such as a missing security patch, misconfiguration, or design flaw, that a threat actor could exploit to compromise confidentiality, integrity, or availability. In the context of the 200-201 exam, this aligns with the core security concept that vulnerabilities are the specific gaps that make an asset susceptible to attack.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Vulnerability

    Why this is correct

    A vulnerability is precisely a weakness or flaw in a system, application, or configuration that a threat actor could exploit to compromise confidentiality, integrity, or availability. This directly matches the stem's requirement for a term describing an exploitable weakness, distinguishing it from a threat (the potential attacker) or risk (the likelihood of exploitation).

  • ✗

    Risk

    Why it's wrong here

    Risk is the potential for loss when a threat exploits a vulnerability, combining likelihood and impact, not the weakness itself. It is tempting because risk assessments reference vulnerabilities heavily. Risk would be the correct answer if the question asked for the combined exposure rather than the flaw.

  • ✗

    Exploit

    Why it's wrong here

    An exploit is the technique or code that takes advantage of a weakness, not the weakness itself. It is tempting because exploits and vulnerabilities appear together in attack discussions. Exploit would be correct if the question asked for the method or tool used to leverage a flaw.

  • ✗

    Threat

    Why it's wrong here

    A threat is the actor or event that could exploit a weakness, not the weakness itself; the stem asks for the vulnerability. It is tempting because threats and vulnerabilities are paired in risk models, so candidates conflate the two. Threat would be correct when identifying who or what could cause harm.

About these practice questions

One of 968 original 200-201 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This 200-201 practice question is part of Courseiva's free Cisco certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 200-201 exam.