SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy

A security analyst is reviewing a new vendor's security posture before integrating their API into the company's core application. The analyst discovers that the vendor's API uses HTTP for all communications, transmits authentication credentials in plaintext, and has no rate limiting implemented. Which of the following risk management concepts is most directly highlighted by these findings?

  1. ARisk appetite
  2. BThreat actor
  3. CVulnerability
  4. DResidual risk
Show answer & explanation

Correct answer: C. Vulnerability

The findings describe weaknesses in the vendor's API security controls (plaintext credentials, no rate limiting, HTTP). These weaknesses are vulnerabilities that could be exploited by threats.

Why the other options are wrong

  • A. Risk appetite is the level of risk an organization is willing to accept, not the specific security weakness.
  • B. A threat actor is an entity that poses a risk, not the weakness in the system.
  • D. Residual risk is the risk remaining after controls have been implemented, not the weakness itself.

Vulnerability

A weakness in an information system, security procedures, internal controls, or implementation that could be exploited by a threat source.

  • Can be exploited by a threat.
  • Often results from design flaws, misconfigurations, or software bugs.
  • Requires a threat to materialize into an incident.

Memory trick: Threats Exploit Vulnerabilities, causing Impact.

More Risk Identification, Monitoring, and Analysis questions