C. Correct Answer – This is a Threat. A cyberattack exploiting a zero-day vulnerability is an active security threat, as it causes harm to the organization.
A. Employee accessing unauthorized files is a vulnerability (insider risk) rather than an external threat.
B. Lack of MFA is a security weakness (vulnerability), not a threat.
This aligns with ISO/IEC 27001:2022 Annex A Control A.8.25 (Assessment and Decision on Information Security Events).
Contribute your Thoughts:
Chosen Answer:
This is a voting comment (?). You can switch to a simple comment. It is better to Upvote an existing comment if you don't have anything to add.
Submit