New Year Sale 2026! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

BCS CISMP-V9 Exam - Topic 2 Question 107 Discussion

Actual exam question for BCS's CISMP-V9 exam
Question #: 107
Topic #: 2
[All CISMP-V9 Questions]

According to ISO/IEC 27000, which of the following is the definition of a vulnerability?

Show Suggested Answer Hide Answer
Suggested Answer: A

The term 'vulnerability' within the context of ISO/IEC 27000 refers to any weakness present in an asset or group of assets that could potentially be exploited by one or more threats. This definition aligns with the concept of vulnerability as a gap in protection efforts that, if not addressed, could allow a threat to compromise the confidentiality, integrity, or availability of an asset. It is important to note that vulnerabilities can be identified in various components of an organization's infrastructure, including hardware, software, processes, and even personnel. Effective information security management involves identifying these vulnerabilities through risk assessments and implementing appropriate controls to mitigate the risk of exploitation.


Contribute your Thoughts:

0/2000 characters
Valentin
3 days ago
I'm going with A). Vulnerabilities are flaws that can be used against you.
upvoted 0 times
...
Flo
8 days ago
A) makes the most sense. Vulnerabilities are weaknesses that can be taken advantage of.
upvoted 0 times
...
Erick
13 days ago
A) is the correct answer. A vulnerability is a weakness that can be exploited by threats.
upvoted 0 times
...
Moon
18 days ago
I’m pretty sure A is correct. It matches what I studied about vulnerabilities being weaknesses that can be exploited.
upvoted 0 times
...
Mertie
24 days ago
I’m confused between A and C. A seems to define a vulnerability better, but C talks about threats, which is also important.
upvoted 0 times
...
Dino
29 days ago
I remember practicing a question like this, and I think A was the right choice because it mentions threats exploiting weaknesses.
upvoted 0 times
...
Kristin
1 month ago
I think a vulnerability is about weaknesses, so I’m leaning towards A, but I’m not entirely sure.
upvoted 0 times
...
Lino
1 month ago
A vulnerability is a weakness that can be exploited, so I'm going with A. Gotta be careful with these tricky definitions.
upvoted 0 times
...
Carolann
1 month ago
Wait, is it B? The impact of a cyber attack? I'm a bit confused now.
upvoted 0 times
...
France
2 months ago
Okay, I've got it. It's definitely A - a weakness that can be exploited by threats.
upvoted 0 times
...
Keneth
2 months ago
Ugh, I'm not sure about this. The definitions all sound similar to me.
upvoted 0 times
...
Aaron
2 months ago
Hmm, I think I know this one. Let me think it through carefully.
upvoted 0 times
...

Save Cancel