ITPEC IP October 2022 Question 37
ITPEC IP October 2022 — Question 37 of 100
Inappropriate password management is a vulnerability because it is a weakness that attackers can exploit. Examples include weak, reused, shared, exposed, or unchanged default passwords. The other choices are hostile agents or attack actions rather than weaknesses in the protected system.
Answer (d)
Why not others:
- computer viruses are threats
- social engineering is an attack technique
- communication tapping is an attack action
Key rule: A threat can cause harm; a vulnerability is the weakness that permits or increases the impact of that threat.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.