Which of the following term BEST describes a weakness that could potentially be exploited?
Correct Answer: A
Explanation/Reference:
Explanation:
A vulnerability is the absence of a countermeasure or a weakness in an in-place countermeasure, and can therefore be exploited.
Incorrect Answers:
B: A risk is the likelihood of a threat agent exploiting a vulnerability and the corresponding business impact.
C: A threat is any potential danger that is associated with the exploitation of a vulnerability.
D: Target Of Evaluation (TOE) refers to the product or system that is the subject of the evaluation.
References:
Harris, Shon, All In One CISSP Exam Guide, 6th Edition, McGraw-Hill, 2013, p. 26
https://en.wikipedia.org/wiki/Common_Criteria