NIST CSF Practice Question: What is a vulnerability in the context of risk assessment? | CyberCertPrep
NISTNIST CSFProfiles RiskEASYFree question
What is a vulnerability in the context of risk assessment?
A.The financial impact of a security incident
B.A type of cybersecurity attack
C.A measure of how likely an attack is to occur
D.A weakness in a system, process, or control that could be exploited by a threat
Why D is correct
A vulnerability is a weakness in a system, process, control, or design that could be exploited by a threat source, potentially resulting in a security breach or other negative outcome.
Know someone studying for NIST CSF? Send them this one.
Where this fits in the NIST CSF exam
Profiles Risk
CSF Profiles and risk: building organizational profiles, prioritizing outcomes, and managing cybersecurity risk.
This question belongs to the "Identify" domain, which makes up about 20% of the NIST CSF exam.
CyberCertPrep gives you 20 free NIST CSF questions per day with this same answer-and-explanation depth, plus timed exam simulations and progress tracking. No card required.
NIST CSF and NIST are trademarks or registered trademarks of their respective owners. CyberCertPrep is an independent exam-preparation resource and is not affiliated with, authorized by, sponsored by, or endorsed by NIST or any other certification body. All study material is independently created; the certification name is used only to identify the exam this resource helps you prepare for.
What is the difference between a Current Profile and a Target Profile?