Courseiva

CISM Information Security Risk Management Practice Question

A healthcare organization is conducting a risk assessment for its electronic health record (EHR) system. The security manager is identifying threats and vulnerabilities. Which TWO of the following are considered vulnerabilities rather than threats? (Choose two.)

⚠ Common exam trap

A common mix-up: candidates confuse threats with vulnerabilities; a disgruntled employee is a threat actor, while unpatched software is a weakness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Unpatched software on the EHR server.

Vulnerabilities are weaknesses or gaps in controls that can be exploited by threats. Unpatched software and weak password policies are examples of such weaknesses because they represent deficiencies in security controls. Threats, on the other hand, are actors or events that can exploit vulnerabilities, such as disgruntled employees, ransomware groups, or natural disasters. Correctly distinguishing between the two is essential for accurate risk assessment.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Unpatched software on the EHR server.

    Why this is correct

    Unpatched software is a weakness in the system that can be exploited by threats. It is a vulnerability because it represents a gap in security controls. Threats are external or internal actors or events that can exploit vulnerabilities. Unpatched software does not act on its own; it requires a threat to cause harm. Therefore, it is correctly classified as a vulnerability.

  • ✓

    Weak password policy allowing short passwords.

    Why this is correct

    A weak password policy is a vulnerability because it introduces a weakness that can be exploited by threats such as brute-force attacks or credential stuffing. The policy itself is a control gap, not an actor. Threats exploit this weakness to gain unauthorized access. Therefore, it is a vulnerability.

  • ✗

    Natural disasters such as floods in the data center region.

    Why it's wrong here

    Natural disasters are threats because they are events that can cause harm by exploiting vulnerabilities such as inadequate physical controls. They are not weaknesses in the system; they are external events with the potential to disrupt operations. Vulnerabilities would be the lack of flood defenses or backup power. Therefore, this is a threat, not a vulnerability.

  • ✗

    A ransomware group targeting healthcare providers.

    Why it's wrong here

    A ransomware group is a threat actor that actively seeks to exploit vulnerabilities. It is an external entity with the intent and capability to cause harm. While the group may target the healthcare sector, it is not a weakness in the system. Vulnerabilities are internal weaknesses; threats are external or internal actors or events. So this is a threat.

  • ✗

    A disgruntled employee with administrative access.

    Why it's wrong here

    A disgruntled employee with administrative access is a threat actor, not a vulnerability. The employee is an individual who could intentionally exploit weaknesses. While their access level may increase the impact, the person themselves is the threat. Vulnerabilities are weaknesses, whereas threats are the sources of harm. Thus, this is a threat, not a vulnerability.

About these practice questions

Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISACA exam blueprint

This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.