SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisEasy

A security analyst is investigating an incident where a critical server was compromised. The attacker gained initial access through a known vulnerability in an unpatched application. After gaining access, the attacker installed a backdoor and moved laterally to other systems. Which of the following risk management concepts BEST describes the initial point of failure that allowed the compromise?

  1. AImpact
  2. BThreat
  3. CResidual Risk
  4. DVulnerability
Show answer & explanation

Correct answer: D. Vulnerability

The initial point of failure was a 'known vulnerability in an unpatched application.' A vulnerability is a weakness that could be exploited by a threat. In this scenario, the unpatched application presented the vulnerability.

Why the other options are wrong

  • A. Impact is the result of a risk materializing, not the initial point of failure.
  • B. A threat is a potential cause of an unwanted incident, not the weakness itself.
  • C. Residual risk is the risk remaining after controls have been implemented, which is not the initial point of failure.

Vulnerability

A weakness or flaw in a system, design, implementation, or operation that could be exploited by a threat source.

  • It's a weakness, not the attack itself.
  • Can be in software, hardware, or human processes.
  • Requires a threat to be exploited.

Memory trick: Threats Exploit Vulnerabilities, Causing Impact.

More Risk Identification, Monitoring, and Analysis questions