FREEBeginner · 10 minute read

Threats, vulnerabilities and attack paths

Connect threats to weaknesses and consequences, then choose a proportionate response.

WHAT YOU WILL LEARN

Learning objectives

  • Distinguish threat, vulnerability and risk
  • Recognize different access paths
  • Prioritise remediation using context
01

Separate the concepts

A vulnerability is a weakness; a threat can exploit or trigger it; risk concerns the likelihood and impact of an outcome. An exposed service with valuable data may deserve a different priority from the same weakness in a tightly isolated test system. Asset context matters.

02

Follow the path

Common paths include deceptive messages, stolen credentials, vulnerable services and excessive permissions. Defense should address the path rather than assuming a single tool covers everything. Reducing exposure, patching, limiting access and monitoring can complement each other.

APPLIED EXAMPLE

Put it in context

A fictional company identifies a vulnerable application reachable from the internet. It evaluates exposure and business impact, applies an approved mitigation, schedules remediation and verifies the result.

Illustrative scenario for learning, not a claim about a verified customer incident.

Common mistakes

  • Ranking only by a headline score
  • Ignoring exposure and business impact
  • Treating a workaround as permanent without review

Your practical checklist

Checklist ticks are temporary and are not recorded as account progress.

MINI RECAP

Prioritise with context, record temporary mitigations and verify that the weakness has actually been addressed.

Put your understanding to the test.

Further authoritative reading ↗