Courseiva
Security Principles →hardMultiple Select

ISC2 CC Security Principles Practice Question

An organization is conducting a risk assessment. Which THREE of the following are considered assets? (Select THREE)

⚠ Common exam trap

The CC exam often tests whether candidates can distinguish assets (things of value) from vulnerabilities (weaknesses) and risks (probability/impact combinations), which are frequently mixed in the answer choices.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Customer database

In risk assessment, an asset is anything of value to the organization that could be affected by a threat, so the customer database (B) qualifies because it holds valuable data whose loss or exposure would harm the business. The firewall (D) is a tangible asset—hardware or software that protects the network and represents a resource the organization owns and depends on. Employee expertise (E) is an intangible asset, since the knowledge, skills, and experience of staff are valuable resources that can be lost through turnover or social engineering. The probability of a data breach (A) is not an asset but a likelihood or risk factor used to estimate how often a threat might occur. A vulnerability in software (C) is a weakness or gap in a control, not something of value, so it is a risk element rather than an asset.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Probability of a data breach

    Why it's wrong here

    Probability estimates how likely an incident is, forming part of the likelihood side of risk calculation, not an asset that holds value to the organisation. It is tempting because likelihood is essential to risk assessment, but it would be the correct answer when the question asks how risk is quantified rather than what is being protected.

  • ✓

    Customer database

    Why this is correct

    A customer database is an information asset: it holds valuable data the organisation must protect, and it carries risk exposure if compromised, lost or corrupted. Risk assessments inventory such assets before identifying threats and vulnerabilities, making the database a legitimate asset in this scenario.

  • ✗

    Vulnerability in software

    Why it's wrong here

    A vulnerability is a weakness that a threat could exploit, so it belongs in the threat or vulnerability category, not among the assets being protected. It is tempting because vulnerabilities are central to risk assessment, but they would be the correct answer when the question asks what a threat exploits rather than what holds value.

  • ✓

    Firewall

    Why this is correct

    A firewall is an asset because it is a tangible security control with value to the organization, requiring protection, patching and configuration management. It falls within the risk assessment scope alongside other hardware, software, data and people assets.

  • ✓

    Employee expertise

    Why this is correct

    Employee expertise is an intangible asset: the accumulated knowledge and skills staff apply to organisational processes. Risk assessments must inventory it because losing key personnel degrades operations, so it satisfies the stem's requirement to identify assets alongside tangible items.

About these practice questions

One of 989 original CC practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This CC practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CC exam.