- Home
- All questions
- Question 108
CISSP study material · question 108 of 500
An assessor adds SQL injection to the risk register of a system that stores everything in flat files and runs no database engine. Why does NIST SP 800-30 treat this as an error?
Show the answer
Answer: C. Susceptibility requires a vulnerability the threat can actually reach, and there is none here.
SP 800-30 states an organisation is not susceptible where a threat cannot exploit a vulnerability to cause harm; without a database management system there is no injection exposure.
Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 footnote 27