Courseiva
Security Principles →hardMultiple Choice

ISC2 CC Security Principles Practice Question

A security analyst is investigating a potential breach. The analyst discovers that an attacker gained access to a server by exploiting a known vulnerability that was not patched. The attacker then installed malware that encrypted critical files and demanded payment. Which of the following best describes the role of the unpatched vulnerability in this incident?

⚠ Common exam trap

The trap here is mixing up the definitions of threat, vulnerability, risk, and impact, especially when they appear together in a scenario.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

It is a weakness that was exploited by a threat.

The unpatched vulnerability is a weakness in the system that was exploited by a threat (the attacker). In risk management, a vulnerability is a flaw or gap that can be leveraged to compromise security. The threat is the actor or event that exploits the vulnerability, and the risk is the potential for loss. The impact is the resulting damage. Therefore, the vulnerability's role is that of a weakness exploited by a threat, making it the correct description.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    It is the risk that materialized.

    Why it's wrong here

    Risk is the potential for loss or damage when a threat exploits a vulnerability. The unpatched vulnerability itself is not the risk; rather, it contributes to the risk. The risk materialized when the attacker exploited the vulnerability and caused harm. The vulnerability is a component of the risk, but it is not the risk itself. The risk is the combination of the threat, vulnerability, and impact.

  • ✗

    It is the impact of the security incident.

    Why it's wrong here

    Impact refers to the damage or loss resulting from a security incident, such as data loss, financial cost, or reputational harm. The unpatched vulnerability is not the impact; it is the weakness that enabled the incident. The impact here is the encrypted files and the ransom demand. The vulnerability is a contributing factor, not the consequence.

  • ✓

    It is a weakness that was exploited by a threat.

    Why this is correct

    A vulnerability is a weakness or flaw in a system that can be exploited by a threat. In this case, the unpatched software is the vulnerability. The attacker (threat) exploited this weakness to gain access and deploy malware. This is the correct definition and role of the vulnerability in the incident. It is the specific flaw that allowed the breach to occur.

  • ✗

    It is the threat that exploited the system.

    Why it's wrong here

    A threat is any potential danger that can exploit a vulnerability to cause harm. In this scenario, the threat is the attacker or the malware, not the unpatched software. The unpatched vulnerability is a weakness that the threat exploited. Confusing the vulnerability with the threat is a common mistake, but they are distinct concepts in risk management.

About these practice questions

Courseiva writes every CC question from scratch — 989 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.