Open cardosec

Case A0E2A5 · GRC · L1 Foundations

Risk vs Threat vs Vulnerability

Practise as: Explain it · Interview

Interview questionExplain the difference between a risk, a threat, and a vulnerability, with one example tying them together.

  1. 01 What is it?
  2. 02 How is it abused?
  3. 03 How do you stop it?
What a strong answer covers

Try it out loud first. Then check yourself:

  1. Threat: an actor or event that could cause harm (ransomware crew, insider, flood). You rarely control it.
  2. Vulnerability: a weakness a threat can exploit, e.g. unpatched VPN appliance, missing MFA, weak process.
  3. Risk: likelihood a threat exploits a vulnerability x business impact. Asset value is what makes it matter.
  4. Example: ransomware gang (threat) + unpatched Citrix (vuln) on a payroll server (asset) = outage/extortion risk.
  5. Treatment options: mitigate, transfer (insurance/contract), avoid (retire system), or formally accept.

If the interviewer pushes back

  • If you cannot change the threat, which levers actually move the risk score, and how do you prove it moved?
  • How does residual risk differ from inherent risk, and who should sign off on accepting it?

Go deeper

cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.