Study. uk . com
  1. Home
  2. All questions
  3. Question 108

CISSP study material · question 108 of 500

An assessor adds SQL injection to the risk register of a system that stores everything in flat files and runs no database engine. Why does NIST SP 800-30 treat this as an error?

  1. Injection is an application weakness and belongs in a separate application register.
  2. The risk should be recorded but transferred to the software supplier.
  3. Susceptibility requires a vulnerability the threat can actually reach, and there is none here.
  4. The threat is real but the likelihood should be recorded as low rather than omitted.
Show the answer

Answer: C. Susceptibility requires a vulnerability the threat can actually reach, and there is none here.

SP 800-30 states an organisation is not susceptible where a threat cannot exploit a vulnerability to cause harm; without a database management system there is no injection exposure.

Source: NIST SP 800-30 Rev. 1 (NIST) — SP 800-30 Rev. 1 > 2.3.1 footnote 27

Challenge yourself on this topic → Study as cards