Courseiva
easyMultiple Choice

Vulnerability in Risk Assessment: Definition and Examples

During a risk assessment, the team identifies that a critical database server is not included in the backup schedule. Which risk term best describes this condition?

Quick Answer

The answer is vulnerability. A vulnerability is any weakness in an asset or control that a threat could exploit, and a critical database server missing from the backup schedule represents a clear gap in data protection and disaster recovery. This absence of a necessary control creates susceptibility to data loss, making it a classic vulnerability rather than an active threat or exploit. On the Systems Security Certified Practitioner SSCP exam, this concept tests your ability to distinguish between vulnerabilities, threats, and risks during a risk assessment—a common trap is confusing a missing control with a threat actor. Remember the memory tip: a vulnerability is a “hole” in your armor, not the arrow (threat) or the act of being hit (exploit).

⚠ Common exam trap

ISC2 often tests the distinction between a vulnerability (a weakness) and a threat (a potential danger), tricking candidates into selecting 'Threat' because they associate the missing backup with a potential data loss event, rather than recognizing it as the underlying weakness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Vulnerability

A vulnerability is a weakness in a system that can be exploited by a threat. The database server missing from the backup schedule represents a weakness in the organization's data protection and disaster recovery posture, making it susceptible to data loss. This absence of a control (backup) is a classic example of a vulnerability, not an active threat or an exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Threat

    Why it's wrong here

    A threat is an actor or event that could cause harm, such as ransomware or hardware failure; the absent backup schedule is a weakness, not the threat source. It is tempting because threats exploit such gaps, and threat would be correct when naming the specific agent or circumstance that could trigger loss.

  • ✗

    Risk

    Why it's wrong here

    Risk is the combined likelihood and impact of a threat exploiting a vulnerability; the missing backup is the vulnerability itself, not the risk. It is tempting because the gap does expose the server to potential loss, and risk would be the correct term once likelihood and impact are assessed.

  • ✗

    Exploit

    Why it's wrong here

    An exploit is the technique or code that leverages a vulnerability, whereas the missing backup is the weakness being leveraged. It is tempting because exploits target exactly such gaps, and exploit would be correct when describing the method an attacker uses, such as a worm abusing an unpatched service.

  • ✓

    Vulnerability

    Why this is correct

    A vulnerability is a weakness or gap that a threat could exploit; the missing backup coverage is precisely such a weakness in the database server's protective controls. It is not a threat (no actor or event) nor a risk (no combined likelihood/impact), so it correctly names the condition itself.

About these practice questions

Courseiva writes every SSCP question from scratch — 971 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. In the context of risk assessment, which of the following best describes a vulnerability?

easy
  • A.A potential event that can cause harm
  • B.The likelihood of a threat exploiting a weakness
  • C.An actual occurrence of a harmful event
  • ✓ D.A weakness in a system that can be exploited

Why D: In risk assessment, a vulnerability is specifically a weakness in a system, application, or process that can be exploited by a threat. Option D correctly defines this as a weakness that can be exploited, which aligns with the NIST SP 800-30 definition of vulnerability as a flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system’s security policy.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.