Define threats, vulnerabilities, exploits and mitigations, then relate risk to likelihood and impact.
ThreatVulnerabilityExploitRiskMitigation
01 // Mental model
Start with the big picture.
A potential cause of harm, such as a malicious actor, malware, accident or environmental event.
CCNA focus: Name each part precisely. A threat is not the same as a vulnerability, and a mitigation reduces risk rather than guaranteeing perfect safety.
02 // Building blocks
Know what each part does.
01
Threat
A potential cause of harm, such as a malicious actor, malware, accident or environmental event.
02
Vulnerability
A weakness in technology, configuration, process or behaviour that could be abused.
03
Exploit
A technique or code that takes advantage of a vulnerability.
04
Mitigation
A safeguard that reduces likelihood, impact or both; residual risk remains after controls.
03 // Compare and recognise
Read the clues.
Item
What to remember
Confidentiality
Prevent unauthorised disclosure.
Integrity
Prevent or detect unauthorised modification.
Availability
Keep systems and data accessible when needed.
Defence in depth
Use multiple complementary controls so one failure is not catastrophic.
Read the example from top to bottom, then verify the resulting state. Configuration is only complete when the output matches the intended design.
05 // Exam and troubleshooting
Turn facts into a method.
Prevent unauthorised disclosure.
Prevent or detect unauthorised modification.
Keep systems and data accessible when needed.
Use multiple complementary controls so one failure is not catastrophic.
Exam checkpoint: Name each part precisely. A threat is not the same as a vulnerability, and a mitigation reduces risk rather than guaranteeing perfect safety.
06 // Check yourself
Security Concepts quiz.
1. What is a vulnerability?
2. What is an exploit?
3. Which CIA property prevents unauthorised modification?