SSCP Risk Identification, Monitoring, and Analysis Practice Question
A risk analyst is building a threat model for a new customer-facing web application. The analyst must identify threat sources and classify them appropriately. Which TWO of the following are examples of environmental or natural threat sources that should be documented in the risk assessment? (Choose two.)
⚠ Common exam trap
The trap here is mixing human and technical threat sources into the environmental category, when only naturally occurring physical events qualify.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
A prolonged power outage affecting the cloud region where the application is deployed.
Natural and environmental threat sources originate in the physical world and affect assets regardless of human intent. Flooding and extended power loss both threaten the web application's availability and supporting infrastructure, so they must be documented in the risk assessment to justify continuity, redundancy, and recovery investments.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
A disgruntled former employee who retains knowledge of internal application architecture.
Why it's wrong here
A disgruntled insider is a human, intentional threat source, not an environmental or natural one. While important to assess, it is classified differently and typically addressed through access revocation, monitoring, and separation-of-duties controls. Including it in this category would miscategorize the threat and skew the risk taxonomy.
- ✓
A prolonged power outage affecting the cloud region where the application is deployed.
Why this is correct
Power loss is an environmental threat source, whether caused by grid failure or weather. It threatens availability of the application and its supporting infrastructure, so it must be documented alongside human threats. Mitigations include uninterruptible power supplies, generator testing, and multi-region failover.
- ✗
An organized criminal group targeting the application for financial fraud.
Why it's wrong here
Organized crime is a human, adversarial threat source driven by intent and capability. It requires different treatment such as threat intelligence, fraud controls, and law enforcement coordination. It does not qualify as an environmental or natural threat, so it does not belong in the category requested.
- ✓
A regional flood that could inundate the primary data center hosting the application.
Why this is correct
Flooding is a natural, environmental threat source that can cause availability and integrity loss regardless of any human intent. It belongs in the risk assessment because it affects the same assets as malicious threats and drives decisions about geographic redundancy, backup sites, and business continuity planning.
- ✗
An unstructured software error in a third-party payment library that causes data corruption.
Why it's wrong here
A software defect is a technical threat source, sometimes called an accidental or non-adversarial technical threat. It is distinct from environmental and natural sources, which originate outside the system in the physical world. Classifying it as environmental would distort the threat model and the associated mitigation strategy.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official ISC2 exam blueprint
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.