Case A0E2A5 · GRC · L1 Foundations
Risk vs Threat vs Vulnerability
Practise as: Explain it · Interview
Interview questionExplain the difference between a risk, a threat, and a vulnerability, with one example tying them together.
- 01 What is it?
- 02 How is it abused?
- 03 How do you stop it?
What a strong answer covers
Try it out loud first. Then check yourself:
- Threat: an actor or event that could cause harm (ransomware crew, insider, flood). You rarely control it.
- Vulnerability: a weakness a threat can exploit, e.g. unpatched VPN appliance, missing MFA, weak process.
- Risk: likelihood a threat exploits a vulnerability x business impact. Asset value is what makes it matter.
- Example: ransomware gang (threat) + unpatched Citrix (vuln) on a payroll server (asset) = outage/extortion risk.
- Treatment options: mitigate, transfer (insurance/contract), avoid (retire system), or formally accept.
If the interviewer pushes back
- If you cannot change the threat, which levers actually move the risk score, and how do you prove it moved?
- How does residual risk differ from inherent risk, and who should sign off on accepting it?
Go deeper
cardosec draws a security topic and gives you a clock: explain it out loud with no notes, then see what you covered and what you missed. Free during early access.