ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium
A security team is evaluating potential threats to a new cloud-based customer database. They identify a scenario where a disgruntled former employee, who still retains some old system credentials, could attempt to access and delete customer records. This scenario represents a specific type of risk component. Which component is being described?
- AThreat
- BVulnerability
- CImpact
- DLikelihood
Show answer & explanationAnswer & explanation
Correct answer: A. Threat
A threat is a potential cause of an unwanted incident, which may result in harm to a system or organization. The disgruntled former employee with old credentials represents a 'threat agent' and their potential action (accessing/deleting records) constitutes a 'threat' in this context.
Why the other options are wrong
- B. A vulnerability is a weakness that could be exploited, such as the old system credentials, but the scenario describes the 'potential cause' (the employee's action), not just the weakness.
- C. Impact is the result or consequence of a risk event, such as the deletion of records, not the cause.
- D. Likelihood is the probability of a threat exploiting a vulnerability, not the threat itself.
Threat
A potential cause of an unwanted incident, which may result in harm to a system or organization. It is an agent or event that could exploit a vulnerability.
- Can be intentional (e.g., cyberattack) or unintentional (e.g., natural disaster)
- Requires a threat agent (e.g., hacker, disgruntled employee, storm)
- Acts on a vulnerability to cause harm
Memory trick: TVIL: Threats exploit Vulnerabilities, causing Impact with a certain Likelihood.