easyMultiple ChoiceObjective-mapped
Vulnerability in Risk Assessment: Definition and Examples
During a risk assessment, the team identifies that a critical database server is not included in the backup schedule. Which risk term best describes this condition?
Quick Answer
The answer is vulnerability. A vulnerability is any weakness in an asset or control that a threat could exploit, and a critical database server missing from the backup schedule represents a clear gap in data protection and disaster recovery. This absence of a necessary control creates susceptibility to data loss, making it a classic vulnerability rather than an active threat or exploit. On the Systems Security Certified Practitioner SSCP exam, this concept tests your ability to distinguish between vulnerabilities, threats, and risks during a risk assessment—a common trap is confusing a missing control with a threat actor. Remember the memory tip: a vulnerability is a “hole” in your armor, not the arrow (threat) or the act of being hit (exploit).
⚠ Common exam trap
ISC2 often tests the distinction between a vulnerability (a weakness) and a threat (a potential danger), tricking candidates into selecting 'Threat' because they associate the missing backup with a potential data loss event, rather than recognizing it as the underlying weakness.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Vulnerability
A vulnerability is a weakness in a system that can be exploited by a threat. The database server missing from the backup schedule represents a weakness in the organization's data protection and disaster recovery posture, making it susceptible to data loss. This absence of a control (backup) is a classic example of a vulnerability, not an active threat or an exploit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Threat
Why it's wrong here
A threat is a potential cause of harm (e.g., a hacker), not a weakness.
- ✗
Risk
Why it's wrong here
Risk is the combination of likelihood and impact; this condition is a vulnerability.
- ✗
Exploit
Why it's wrong here
An exploit is a specific attack that takes advantage of a vulnerability.
- ✓
Vulnerability
Why this is correct
The missing backup is a weakness that could lead to data loss.
Go deeper
Related to this question
About these practice questions
Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
Same concept, more angles
1 more way this is tested on SSCP
These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.
Variation 1. In the context of risk assessment, which of the following best describes a vulnerability?
easy- A.A potential event that can cause harm
- B.The likelihood of a threat exploiting a weakness
- C.An actual occurrence of a harmful event
- ✓ D.A weakness in a system that can be exploited
Why D: In risk assessment, a vulnerability is specifically a weakness in a system, application, or process that can be exploited by a threat. Option D correctly defines this as a weakness that can be exploited, which aligns with the NIST SP 800-30 definition of vulnerability as a flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system’s security policy.
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.