Systems Security Certified Practitioner – SSCP – Question0563

Which of the following could be BEST defined as the likelihood of a threat agent taking advantage of a vulnerability?

A.
A risk
B. A residual risk
C. An exposure
D. A countermeasure

Correct Answer: A

Explanation:

Risk is the likelihood of a threat agent taking advantage of a vulnerability and the corresponding business impact. If a firewall has several ports open , there is a higher likelihood that an intruder will use one to access the network in an unauthorized method.
The following answers are incorrect : Residual Risk is very different from the notion of total risk. Residual Risk would be the risks that still exists after countermeasures have been implemented. Total risk is the amount of risk a company faces if it chooses not to implement any type of safeguard.
Exposure: An exposure is an instance of being exposed to losses from a threat agent.
Countermeasure: A countermeasure or a safeguard is put in place to mitigate the potential risk. Examples of countermeasures include strong password management , a security guard.
REFERENCES : SHON HARRIS ALL IN ONE 3rd EDITION Chapter -3: Security Management Practices , Pages : 57-59