hardMultiple Select
CISSP A risk assessment identifies several threats Practice Question
A risk assessment identifies several threats. Which THREE are considered external threats?
⚠ Common exam trap
Candidates often confuse the source of a threat. While human threats can be both internal and external, any threat originating from an entity with authorized access (like a disgruntled employee or an employee making an error) is classified as an internal threat, whereas competitors, hacktivists, and environmental events are external.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hacktivist
Option B (Hacktivist) is correct because a hacktivist is an outside actor who attacks systems to advance a political or social agenda, making it an external threat. Option D (Natural disaster) is correct because events such as floods, fires, and earthquakes originate from the environment outside the organization and are classified as external threats. Option E (Competitor) is correct because a rival organization operating outside the company can conduct espionage, sabotage, or other hostile actions, which is an external threat source. Options A (Insider error) and C (Disgruntled employee) are not external threats because both involve individuals within the organization who already have authorized access, making them internal threats.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Insider error
Why it's wrong here
Insider error, also known as human error, is an internal threat stemming from unintentional mistakes made by authorized personnel, such as misconfigurations, accidental data deletion, or falling victim to phishing scams. While not malicious, these errors can lead to significant security incidents, data breaches, or operational downtime. Its origin within the organization's trusted user base classifies it as an internal, rather than external, threat.
- ✓
Hacktivist
Why this is correct
A hacktivist is an external threat actor who leverages hacking techniques to promote a political or social cause, rather than for direct financial gain. Their motivations are ideological, often targeting organizations whose practices they oppose to disrupt operations, deface websites, or leak sensitive information. This makes them a distinct and significant external threat identified in comprehensive risk assessments.
- ✗
Disgruntled employee
Why it's wrong here
A disgruntled employee represents an internal threat actor, possessing authorized access and insider knowledge that can be leveraged for malicious purposes, such as data theft, system sabotage, or intellectual property exfiltration. While a significant risk due to their privileged position and understanding of internal systems, they operate from within the organization's perimeter. Therefore, if the question implicitly seeks external threats, this option would be incorrect.
- ✓
Natural disaster
Why this is correct
A natural disaster is an external event, uncontrollable by the organization, that can severely disrupt operations, destroy critical infrastructure, and cause significant data loss. Events like earthquakes, floods, hurricanes, or wildfires pose substantial physical and operational threats, necessitating robust business continuity and disaster recovery planning. Its inherent external origin makes it a critical consideration in any comprehensive risk assessment.
- ✓
Competitor
Why this is correct
A competitor can function as an external threat actor, primarily through industrial espionage, intellectual property theft, or aggressive market tactics aimed at gaining an unfair advantage. This can involve attempts to compromise systems for sensitive business intelligence, disrupt services, or damage reputation through illicit means. Their external position and motivation to undermine market standing make them a legitimate threat to assess.
Go deeper
Related to this question
Learn chapter
Identity and Access Management (IAM)
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Threat
A threat is any potential danger that could harm a computer system, network, or data, whether from a malicious hacker, a natural disaster, or an accidental mistake.
About these practice questions
One of 816 original CISSP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.