Courseiva
easyMultiple ChoiceObjective-mapped

Vulnerability in Risk Assessment: Definition and Examples

During a risk assessment, the team identifies that a critical database server is not included in the backup schedule. Which risk term best describes this condition?

Quick Answer

The answer is vulnerability. A vulnerability is any weakness in an asset or control that a threat could exploit, and a critical database server missing from the backup schedule represents a clear gap in data protection and disaster recovery. This absence of a necessary control creates susceptibility to data loss, making it a classic vulnerability rather than an active threat or exploit. On the Systems Security Certified Practitioner SSCP exam, this concept tests your ability to distinguish between vulnerabilities, threats, and risks during a risk assessment—a common trap is confusing a missing control with a threat actor. Remember the memory tip: a vulnerability is a “hole” in your armor, not the arrow (threat) or the act of being hit (exploit).

⚠ Common exam trap

ISC2 often tests the distinction between a vulnerability (a weakness) and a threat (a potential danger), tricking candidates into selecting 'Threat' because they associate the missing backup with a potential data loss event, rather than recognizing it as the underlying weakness.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Vulnerability

A vulnerability is a weakness in a system that can be exploited by a threat. The database server missing from the backup schedule represents a weakness in the organization's data protection and disaster recovery posture, making it susceptible to data loss. This absence of a control (backup) is a classic example of a vulnerability, not an active threat or an exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Threat

    Why it's wrong here

    A threat is a potential cause of harm (e.g., a hacker), not a weakness.

  • Risk

    Why it's wrong here

    Risk is the combination of likelihood and impact; this condition is a vulnerability.

  • Exploit

    Why it's wrong here

    An exploit is a specific attack that takes advantage of a vulnerability.

  • Vulnerability

    Why this is correct

    The missing backup is a weakness that could lead to data loss.

About these practice questions

Courseiva writes every SSCP question from scratch — 920 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

Same concept, more angles

1 more way this is tested on SSCP

These questions test the same concept from different angles. Work through them to make sure you can recognise it however the exam phrases it.

Variation 1. In the context of risk assessment, which of the following best describes a vulnerability?

easy
  • A.A potential event that can cause harm
  • B.The likelihood of a threat exploiting a weakness
  • C.An actual occurrence of a harmful event
  • D.A weakness in a system that can be exploited

Why D: In risk assessment, a vulnerability is specifically a weakness in a system, application, or process that can be exploited by a threat. Option D correctly defines this as a weakness that can be exploited, which aligns with the NIST SP 800-30 definition of vulnerability as a flaw or weakness in system security procedures, design, implementation, or internal controls that could be exercised (accidentally triggered or intentionally exploited) and result in a security breach or a violation of the system’s security policy.

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.