Common Threat Sources
Threats come from many directions. A good IT professional avoids the mistake of thinking that all security problems come from anonymous outsiders.
Threat sources usually include:
- External attackers such as cybercriminals, hacktivists, and opportunistic intruders
- Insiders such as careless employees, disgruntled users, or over-privileged staff
- Environmental events such as fire, flood, power loss, and hardware failure
- Human error such as accidental deletion, wrong configuration, and lost devices
- Supply chain issues such as insecure third-party services, compromised updates, or weak vendor practices
Some threats are intentional, while others are accidental. Both matter. A user who mistakenly posts a spreadsheet with personal data can cause damage almost as serious as a deliberate attacker.
Types of Vulnerabilities
A vulnerability is a weakness that makes a system easier to compromise. Vulnerabilities often appear in these categories:
- Technical vulnerabilities — unpatched software, insecure services, misconfigured firewalls
- Human vulnerabilities — weak passwords, lack of awareness, social engineering susceptibility
- Physical vulnerabilities — unlocked server rooms, exposed network ports, stolen devices
- Process vulnerabilities — no backup plan, no change approval, unclear incident reporting
- Design vulnerabilities — systems built without security requirements from the start
A strong exam point here is that a vulnerability does not automatically mean a breach has happened. It means the system is susceptible. Once exploited, it becomes part of an attack.
Security Controls and Their Categories
ProReviewer — locked
Drills, code labs, and full solutions.
Basic Risk Assessment
ProReviewer — locked
Drills, code labs, and full solutions.
Practice & Exam Drills — Lesson 2
ProReviewer — locked
Drills, code labs, and full solutions.