What is a vulnerability?

Boost your Adjudicator skills with our certification test. Prepare with multiple choice questions, detailed answers, and expert tips. Ace your exam with confidence!

Multiple Choice

What is a vulnerability?

Explanation:
A vulnerability is a weakness in a system, process, or control that could be exploited by a threat to cause harm. It’s the opening that makes an attack possible, not the harm itself, nor the likelihood of an attack. For example, unpatched software or weak access controls create vulnerabilities that an attacker could exploit. A threat is the potential actor or event that could take advantage of that weakness. Risk combines the chance that a threat will exploit the vulnerability with the resulting impact. Exposure refers to being open to harm due to insufficient protections, but it isn’t the weakness itself. So, describing a weakness that can be exploited best fits the concept of a vulnerability.

A vulnerability is a weakness in a system, process, or control that could be exploited by a threat to cause harm. It’s the opening that makes an attack possible, not the harm itself, nor the likelihood of an attack. For example, unpatched software or weak access controls create vulnerabilities that an attacker could exploit. A threat is the potential actor or event that could take advantage of that weakness. Risk combines the chance that a threat will exploit the vulnerability with the resulting impact. Exposure refers to being open to harm due to insufficient protections, but it isn’t the weakness itself. So, describing a weakness that can be exploited best fits the concept of a vulnerability.

Subscribe

Get the latest from Examzify

You can unsubscribe at any time. Read our privacy policy