SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy
A security analyst is investigating an incident where a critical server was compromised. The attacker gained initial access through a known vulnerability in an unpatched application. After gaining access, the attacker installed a backdoor and moved laterally to other systems. Which of the following risk management concepts BEST describes the initial point of failure that allowed the compromise?
- AImpact
- BThreat
- CResidual Risk
- DVulnerability
Show answer & explanationAnswer & explanation
Correct answer: D. Vulnerability
The initial point of failure was a 'known vulnerability in an unpatched application.' A vulnerability is a weakness that could be exploited by a threat. In this scenario, the unpatched application presented the vulnerability.
Why the other options are wrong
- A. Impact is the result of a risk materializing, not the initial point of failure.
- B. A threat is a potential cause of an unwanted incident, not the weakness itself.
- C. Residual risk is the risk remaining after controls have been implemented, which is not the initial point of failure.
Vulnerability
A weakness or flaw in a system, design, implementation, or operation that could be exploited by a threat source.
- It's a weakness, not the attack itself.
- Can be in software, hardware, or human processes.
- Requires a threat to be exploited.
Memory trick: Threats Exploit Vulnerabilities, Causing Impact.