Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

A risk analyst is documenting threats for a new cloud-hosted application. The analyst must classify threat sources. Which of the following is an example of an environmental threat source rather than a human threat source?

⚠ Common exam trap

Watch out — candidates often confuse a technical flaw such as a vulnerable library with an environmental threat source, when each category drives a different set of controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

A flood that damages the regional data center hosting the application.

Threat sources are grouped into human, technical, and environmental categories. A flood is a classic environmental source because it stems from natural conditions rather than from a person or a code defect. Correct classification guides the risk response: environmental threats call for geographic redundancy, resilient facilities, and continuity planning, while human and technical sources call for access controls, monitoring, and remediation of flaws.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    A flood that damages the regional data center hosting the application.

    Why this is correct

    Floods, fires, earthquakes, and similar natural events are environmental threat sources because they originate from physical surroundings rather than from people or technology. Classifying them correctly matters because environmental risks are typically addressed with geographic redundancy, backup sites, and facility controls, not with access management or patching. This distinction drives which controls a risk treatment plan selects.

  • ✗

    A software bug in a third-party library used by the application.

    Why it's wrong here

    A software defect is a technical threat source, arising from flaws in code, configuration, or design rather than from nature or from a malicious actor. It is remediated through patching, code review, and dependency management. Treating it as environmental would misdirect the risk response toward physical or geographic controls that do nothing to address the vulnerable library.

  • ✗

    A disgruntled administrator with privileged access to the application database.

    Why it's wrong here

    A disgruntled administrator is a human threat source, specifically an insider with authorized access who may abuse it. Insider threats are classified under human sources because the motivation and capability come from a person, even when the person holds legitimate credentials. Environmental sources, by contrast, arise from conditions such as power, climate, or location rather than intentional human action.

  • ✗

    An organized criminal group targeting the application for ransomware.

    Why it's wrong here

    An organized criminal group is clearly a human threat source with intent, capability, and a motive such as financial gain. Threat modeling for this source focuses on controls like segmentation, endpoint detection, and backups rather than on facility resilience. Misclassifying it as environmental would lead to the wrong control selection and an inaccurate risk register entry.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official ISC2 exam blueprint

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.