ITPEC IP April 2025 Question 37
ITPEC IP April 2025 — Question 37 of 100
Inappropriate password management is a vulnerability — it is a weakness that a threat can exploit.
Examples include weak or reused passwords, shared credentials, exposed password notes, or failure to change compromised credentials. Such practices create an opening for unauthorized access. The other options describe malicious agents or actions rather than the weakness that enables them.
Answer (d)
Why not others:
- (a) Computer viruses are malware threats
- (b) Social engineering is an attack method that manipulates people
- (c) Tapping communications data is an interception attack
Key rule: A threat is something capable of causing harm; a vulnerability is a weakness; risk arises when a threat can exploit a vulnerability and cause impact.
AI-generated — may contain errors
The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.
This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.