Courseiva

SSCP Risk Identification, Monitoring, and Analysis Practice Question

Which of the following is a common vulnerability source that would be documented in a risk register?

⚠ Common exam trap

ISC2 often tests the distinction between vulnerability sources (like CVE entries) and security controls or monitoring outputs (like password policies, intrusion alerts, or firewall logs), trapping candidates who confuse operational data with vulnerability documentation.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

CVE entries

D is correct because CVE (Common Vulnerabilities and Exposures) entries are standardized identifiers for known security vulnerabilities, making them a direct source of vulnerability information that should be documented in a risk register. A risk register captures identified risks, including specific vulnerabilities, and CVE entries provide the precise technical details needed to assess and track those risks.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Password policies

    Why it's wrong here

    Password policies are governance documents stating required configuration, not a source that discovers weaknesses in systems. They would be the correct answer if the question asked for a control or standard, rather than an input feeding vulnerability identification.

  • ✗

    Intrusion alerts

    Why it's wrong here

    Intrusion alerts are detection output, not a vulnerability source; they record that exploitation is occurring, whereas a risk register documents weaknesses such as misconfigurations or unpatched software. Tempting because alerting feeds incident response and monitoring, and would be the right focus when triaging active attacks rather than cataloguing underlying exposures.

  • ✗

    Firewall logs

    Why it's wrong here

    Firewall logs record permitted and denied network traffic, which is monitoring output rather than a source identifying weaknesses in assets. Logs feed detection and forensics; a vulnerability source would be a scanner, vendor advisory or penetration test finding.

  • ✓

    CVE entries

    Why this is correct

    CVE entries provide standardised identifiers for publicly disclosed software flaws, giving the risk register concrete, traceable vulnerability data. They satisfy the stem's requirement for a common vulnerability source by cataloguing specific weaknesses that feed directly into likelihood and impact assessments, unlike broader threat categories or control gaps.

About these practice questions

This SSCP question is part of Courseiva's 971-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.