SSCP Risk Identification, Monitoring, and Analysis Practice Question
Which of the following is a common vulnerability source that would be documented in a risk register?
⚠ Common exam trap
ISC2 often tests the distinction between vulnerability sources (like CVE entries) and security controls or monitoring outputs (like password policies, intrusion alerts, or firewall logs), trapping candidates who confuse operational data with vulnerability documentation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
CVE entries
D is correct because CVE (Common Vulnerabilities and Exposures) entries are standardized identifiers for known security vulnerabilities, making them a direct source of vulnerability information that should be documented in a risk register. A risk register captures identified risks, including specific vulnerabilities, and CVE entries provide the precise technical details needed to assess and track those risks.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Password policies
Why it's wrong here
Password policies are governance documents stating required configuration, not a source that discovers weaknesses in systems. They would be the correct answer if the question asked for a control or standard, rather than an input feeding vulnerability identification.
- ✗
Intrusion alerts
Why it's wrong here
Intrusion alerts are detection output, not a vulnerability source; they record that exploitation is occurring, whereas a risk register documents weaknesses such as misconfigurations or unpatched software. Tempting because alerting feeds incident response and monitoring, and would be the right focus when triaging active attacks rather than cataloguing underlying exposures.
- ✗
Firewall logs
Why it's wrong here
Firewall logs record permitted and denied network traffic, which is monitoring output rather than a source identifying weaknesses in assets. Logs feed detection and forensics; a vulnerability source would be a scanner, vendor advisory or penetration test finding.
- ✓
CVE entries
Why this is correct
CVE entries provide standardised identifiers for publicly disclosed software flaws, giving the risk register concrete, traceable vulnerability data. They satisfy the stem's requirement for a common vulnerability source by cataloguing specific weaknesses that feed directly into likelihood and impact assessments, unlike broader threat categories or control gaps.
Go deeper
Related to this question
About these practice questions
This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.