ISC2 CC Security Principles Practice Question
An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)
⚠ Common exam trap
The CC exam often tests whether candidates can distinguish assets (things of value) from vulnerabilities (weaknesses) and risks (probability/impact combinations), which are frequently mixed in the answer choices.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Customer database
In risk assessment, an asset is anything of value to the organization that could be affected by a threat, so the customer database (B) qualifies because it holds valuable data whose loss or exposure would harm the business. The firewall (D) is a tangible asset—hardware or software that protects the network and represents a resource the organization owns and depends on. Employee expertise (E) is an intangible asset, since the knowledge, skills, and experience of staff are valuable resources that can be lost through turnover or social engineering. The probability of a data breach (A) is not an asset but a likelihood or risk factor used to estimate how often a threat might occur. A vulnerability in software (C) is a weakness or gap in a control, not something of value, so it is a risk element rather than an asset.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Probability of a data breach
Why it's wrong here
Probability estimates how likely an incident is, forming part of the likelihood side of risk calculation, not an asset that holds value to the organisation. It is tempting because likelihood is essential to risk assessment, but it would be the correct answer when the question asks how risk is quantified rather than what is being protected.
- ✓
Customer database
Why this is correct
A customer database is an information asset: it holds valuable data the organisation must protect, and it carries risk exposure if compromised, lost or corrupted. Risk assessments inventory such assets before identifying threats and vulnerabilities, making the database a legitimate asset in this scenario.
- ✗
Vulnerability in software
Why it's wrong here
A vulnerability is a weakness that a threat could exploit, so it belongs in the threat or vulnerability category, not among the assets being protected. It is tempting because vulnerabilities are central to risk assessment, but they would be the correct answer when the question asks what a threat exploits rather than what holds value.
- ✓
Firewall
Why this is correct
A firewall is an asset because it is a tangible security control with value to the organization, requiring protection, patching and configuration management. It falls within the risk assessment scope alongside other hardware, software, data and people assets.
- ✓
Employee expertise
Why this is correct
Employee expertise is an intangible asset: the accumulated knowledge and skills staff apply to organisational processes. Risk assessments must inventory it because losing key personnel degrades operations, so it satisfies the stem's requirement to identify assets alongside tangible items.
Go deeper
Related to this question
Learn chapter
Risk Management and Security Controls
Key term
Social engineering
Social engineering is the psychological manipulation of people into divulging confidential information or performing actions that compromise security.
Key term
Likelihood
Likelihood is the estimated probability that a specific threat will exploit a vulnerability, causing harm to an IT asset or system.
About these practice questions
One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.