Courseiva
Security →hardMultiple Choice

FC0-U71 Security Practice Question

A security analyst is explaining the difference between a threat and a vulnerability. Which statement accurately describes this difference?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A threat is a potential cause of harm, and a vulnerability is a weakness that can be exploited.

A vulnerability is a weakness, while a threat is a potential danger that exploits that weakness.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    A vulnerability is a risk, and a threat is a countermeasure.

    Why it's wrong here

    A vulnerability is a weakness, not a risk, and a threat is a potential cause of harm, not a countermeasure. This option is tempting because risk and countermeasures appear in security discussions, but neither term matches the definitions tested here.

  • ✗

    A threat is a weakness in a system, and a vulnerability is an attack that exploits it.

    Why it's wrong here

    This reverses the definitions: a threat is a potential cause of harm, while a vulnerability is the weakness itself. It is tempting because attacks do exploit weaknesses, but the statement mislabels which term describes the weakness and which describes the attacker or event.

  • ✓

    A threat is a potential cause of harm, and a vulnerability is a weakness that can be exploited.

    Why this is correct

    A threat is any potential occurrence or actor that could cause harm, whereas a vulnerability is an internal weakness — such as a flaw or misconfiguration — that a threat can exploit. This distinction separates external causes from exploitable conditions, matching the stem's request to differentiate the two terms accurately.

  • ✗

    A vulnerability is a potential harm, and a threat is likelihood times impact.

    Why it's wrong here

    A vulnerability is a weakness, not potential harm, and likelihood times impact defines risk, not threat. The option is tempting because risk calculations feature in security analysis, but it conflates three distinct concepts the question asks you to separate.

About these practice questions

Courseiva writes every FC0-U71 question from scratch — 988 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

2 more ways this is tested on FC0-U71

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. What is the difference between a threat and a vulnerability?

easy
  • ✓ A.A threat is a potential harm, and a vulnerability is a weakness
  • B.They are the same thing
  • C.A threat is a weakness, and a vulnerability is a danger
  • D.A threat is a type of malware, and a vulnerability is a type of attack

Why A: A threat is a potential source of harm (e.g., a hacker), while a vulnerability is a weakness that can be exploited (e.g., unpatched software).

Variation 2. Which of the following is a key difference between a vulnerability and a threat in cybersecurity?

medium
  • A.A vulnerability is a potential harm, while a threat is a weakness
  • B.A vulnerability is always present, while a threat is actively exploited
  • ✓ C.A vulnerability is a weakness, while a threat is a potential danger
  • D.A vulnerability can be patched, but a threat cannot be mitigated

Why C: A vulnerability is a weakness or flaw in a system (e.g., unpatched software, misconfiguration) that could be exploited, while a threat is any potential danger or actor that could exploit that weakness (e.g., a hacker, malware, or natural disaster). Option C correctly captures this weakness-versus-danger distinction. Understanding the difference is essential for risk assessment, since risk = threat × vulnerability × impact.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This FC0-U71 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the FC0-U71 exam.