ISC2 Certified in Cybersecurity (CC)Security PrinciplesMedium

A security team is evaluating potential threats to a new cloud-based customer database. They identify a scenario where a disgruntled former employee, who still retains some old system credentials, could attempt to access and delete customer records. This scenario represents a specific type of risk component. Which component is being described?

  1. AThreat
  2. BVulnerability
  3. CImpact
  4. DLikelihood
Show answer & explanation

Correct answer: A. Threat

A threat is a potential cause of an unwanted incident, which may result in harm to a system or organization. The disgruntled former employee with old credentials represents a 'threat agent' and their potential action (accessing/deleting records) constitutes a 'threat' in this context.

Why the other options are wrong

  • B. A vulnerability is a weakness that could be exploited, such as the old system credentials, but the scenario describes the 'potential cause' (the employee's action), not just the weakness.
  • C. Impact is the result or consequence of a risk event, such as the deletion of records, not the cause.
  • D. Likelihood is the probability of a threat exploiting a vulnerability, not the threat itself.

Threat

A potential cause of an unwanted incident, which may result in harm to a system or organization. It is an agent or event that could exploit a vulnerability.

  • Can be intentional (e.g., cyberattack) or unintentional (e.g., natural disaster)
  • Requires a threat agent (e.g., hacker, disgruntled employee, storm)
  • Acts on a vulnerability to cause harm

Memory trick: TVIL: Threats exploit Vulnerabilities, causing Impact with a certain Likelihood.

More Security Principles questions