350-201 Question 28
Single answerA financial institution has recently implemented a risk analysis process to strengthen its cybersecurity posture. During the assessment, they identified that their customer database server is exposed to a known vulnerability due to outdated software, and a recent threat report highlights active exploitation of this vulnerability by attackers. Which combination of elements in the risk analysis process does this scenario represent?
- A
Asset: customer database server, Vulnerability: outdated software, Threat: active exploitation by attackers
- B
Asset: customer database server, Vulnerability: active exploitation by attackers, Threat: outdated software
- C
Asset: outdated software, Vulnerability: customer database server, Threat: active exploitation by attackers
- D
Asset: attackers, Vulnerability: outdated software, Threat: customer database server
Show answer and explanation
Correct answer: A
Explanation
In a risk analysis, the asset is what needs protection (e.g., a customer database server), the vulnerability is the weakness that could be exploited (e.g., outdated software), and the threat is the potential action or entity that exploits the vulnerability (e.g., active exploitation by attackers). Properly identifying these elements is critical for effective risk management.
- A. Correct.
Correct. The customer database server is the asset. The outdated software is the vulnerability, and the active exploitation by attackers is the threat.
- B. Incorrect.
Incorrect. The vulnerability and threat are reversed in this option. The outdated software is the vulnerability, and the active exploitation is the threat.
- C. Incorrect.
Incorrect. The asset is misidentified as the outdated software, which is actually the vulnerability. The customer database server is the asset.
- D. Incorrect.
Incorrect. Attackers are not the asset; they are part of the threat. The asset is the customer database server.