Complete Questions and Detailed Solutions 2026
SECTION 1: FUNDAMENTAL CONCEPTS (Questions 1-20)
Question 1
Which statement best defines a threat in the context of information security?
A) A confirmed security breach that has already occurred
B) Any potential danger that could exploit a vulnerability
C) A software flaw or weakness in a system
D) The likelihood that a risk will materialize
ANSWER: B
Rationale: A threat is any potential danger that could exploit a vulnerability to cause harm to an asset.
Option A describes an incident, Option C describes a vulnerability, and Option D describes probability.
Threats are external or internal actors/events that can take advantage of weaknesses.
Question 2
What is the relationship between a threat, a vulnerability, and a risk?
A) Risk = Threat × Vulnerability
B) Risk = Threat + Vulnerability
C) Risk = Threat / Vulnerability
D) Risk = Vulnerability - Threat
ANSWER: A
,Rationale: Risk is the product of threat and vulnerability. A threat exploits a vulnerability to create risk.
Without either a threat or a vulnerability, there is no risk. This fundamental formula underpins all
security risk assessment methodologies.
Question 3
Which of the following is NOT one of the three primary security objectives (CIA triad)?
A) Confidentiality
B) Integrity
C) Authenticity
D) Availability
ANSWER: C
Rationale: The CIA triad consists of Confidentiality, Integrity, and Availability. Authenticity, while
important, is a separate security principle often associated with non-repudiation and identity
verification, not one of the three core CIA objectives.
Question 4
A vulnerability is best described as:
A) A malicious actor attempting to breach security
B) The potential impact of a security incident
C) A weakness or gap in security protection efforts
D) The process of identifying security risks
ANSWER: C
,Rationale: A vulnerability is a weakness or gap in protection efforts. It is a flaw, weakness, or absence of
a safeguard that could be exploited by a threat. Vulnerabilities are internal to the system and are within
the organization's control to remediate.
Question 5
What are the four key components of a Threat and Risk Assessment?
A) Asset identification, Threat identification, Vulnerability assessment, Risk evaluation
B) Asset identification, Risk transfer, Insurance purchase, Monitoring
C) Threat identification, Vulnerability scanning, Patch management, Auditing
D) Risk identification, Risk analysis, Risk response, Risk monitoring
ANSWER: A
Rationale: The four key components of a threat and risk assessment are: (1) Asset identification—
identifying what needs protection, (2) Threat identification—identifying potential threats, (3)
Vulnerability assessment—identifying weaknesses, and (4) Risk evaluation—assessing likelihood and
impact.
Question 6
Which of the following is an example of an internal threat?
A) A nation-state hacking group
B) A disgruntled employee stealing data
C) A competitor conducting industrial espionage
D) A cybercriminal organization
ANSWER: B
, Rationale: Internal threats originate from within the organization. A disgruntled employee represents an
insider threat because they have authorized access and inside knowledge. Nation-state groups,
competitors, and cybercriminal organizations are all external threat actors.
Question 7
What is the primary purpose of establishing context in a security risk assessment?
A) To determine the budget for security controls
B) To identify the scope, boundaries, and objectives of the assessment
C) To select the appropriate security vendor
D) To conduct penetration testing
ANSWER: B
Rationale: Establishing context defines the scope, boundaries, and objectives of the risk assessment. It
ANSWERs questions about what systems are being assessed, what assets are involved, what the
organizational risk appetite is, and what regulatory requirements apply.
Question 8
Which factor is LEAST likely to be used when ranking risks?
A) The likelihood of a threat occurring
B) The potential impact of the risk
C) The specific identity of the threat actor
D) The vulnerability severity
ANSWER: C
Rationale: Risk ranking typically focuses on likelihood and impact. While understanding the threat actor
is important for threat intelligence, the specific identity is less relevant than the capability, intent, and
likelihood of exploitation when ranking risks. Risk = Likelihood × Impact.