SSCP Risk Identification, Monitoring, and Analysis Practice Question
Which TWO of the following are examples of technical threat sources that should be considered during risk identification?
⚠ Common exam trap
Test-takers frequently confuse threat categories, mistakenly classifying human-based threats like social engineering or insider actions as technical threat sources, when the SSCP exam strictly separates technical threats (hardware/software failures) from human and environmental threats.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Hardware failure
Hardware failure (B) is a technical threat source because it arises from the failure of IT infrastructure components such as servers, disks, or network devices, which is a classic technology-originated risk considered in risk identification. Software bug (D) is also a technical threat source, as flaws in application or system code can introduce vulnerabilities and cause failures or exploitable conditions. These two are correct because they stem from technology itself rather than from natural events or deliberate human behavior. In contrast, earthquake (A) is an environmental/natural threat source, unauthorized access by employee (C) is a human/internal threat source, and social engineering (E) is a human-driven threat that exploits people rather than a technical fault.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Earthquake
Why it's wrong here
An earthquake is a natural or environmental threat source, lacking any technical mechanism such as exploitation of software or network weaknesses. It is tempting because it appears in business continuity and risk registers, and would be the correct choice when the question asks about environmental or physical threat sources.
- ✓
Hardware failure
Why this is correct
Hardware failure counts as a technical threat source because it arises from the failure of technology components themselves, such as disk crashes or component degradation, rather than from environmental forces or human actors. Risk identification must catalogue it alongside software and network weaknesses.
- ✗
Unauthorized access by employee
Why it's wrong here
Unauthorised access by an employee is an insider threat category describing an actor's action, not a technical threat source like a vulnerability or attack vector. It is tempting because insider misuse features in risk assessments, and would be correct when the question asks about threat actors or human-origin risk sources.
- ✓
Software bug
Why this is correct
A software bug is a technical threat source because the vulnerability originates within the technology itself, such as flawed code enabling crashes or exploitation, rather than from environmental events or deliberate human action. It belongs in the technical category during risk identification.
- ✗
Social engineering
Why it's wrong here
Social engineering is a human-focused threat exploiting trust and manipulation, not a technical source such as malware or misconfiguration. It is tempting because it appears in risk registers and threat taxonomies, and would be the correct classification when the scenario asks about people-centric or non-technical threat vectors.
Go deeper
Related to this question
About these practice questions
One of 971 original SSCP practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This SSCP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the SSCP exam.