๐Ÿ“ข Too many exams? Donโ€™t know which one suits you best? Book Your Free Expert ๐Ÿ‘‰ call Now!

  • google app store apple app store
  • โœ–

      Question

      What is the difference between 'vulnerability',

      'threat', and 'risk' in cybersecurity?
      A All three terms describe the same concept โ€” potential security issues Correct Answer Incorrect Answer
      B Vulnerability is a weakness in a system; Threat is a potential danger that exploits a vulnerability; Risk is the likelihood and impact of a threat exploiting a vulnerability Correct Answer Incorrect Answer
      C Vulnerability is an attack from a hacker; Threat is the attacker who attacks the system; Risk is the damaged caused due to the attack on a system Correct Answer Incorrect Answer
      D VVulnerability applies to software; Threat applies to hardware; Risk applies to data, software and hardware Correct Answer Incorrect Answer
      E Vulnerability is internal; Threat is external; Risk is financial impact only Correct Answer Incorrect Answer

      Solution

      Vulnerability is weakness (unpatched software, misconfiguration, weak password policy). Threat is potential event that exploits a vulnerability (hacker, malware, insider threat, natural disaster). Risk = Threat ร— Vulnerability ร— Impact = the probability and consequence of a threat exploiting a vulnerability. Formula: Risk = Threat ร— Vulnerability ร— Asset Value. Banks must conduct regular Vulnerability Assessments and Penetration Testing (VAPT),ย  mandated by RBI, to identify and remediate vulnerabilities before threats exploit them.

      Practice Next

      Relevant for Exams:

      ask-question