WHAT YOU WILL LEARN
Learning objectives
- Distinguish threat, vulnerability and risk
- Recognize different access paths
- Prioritise remediation using context
Separate the concepts
A vulnerability is a weakness; a threat can exploit or trigger it; risk concerns the likelihood and impact of an outcome. An exposed service with valuable data may deserve a different priority from the same weakness in a tightly isolated test system. Asset context matters.
Follow the path
Common paths include deceptive messages, stolen credentials, vulnerable services and excessive permissions. Defense should address the path rather than assuming a single tool covers everything. Reducing exposure, patching, limiting access and monitoring can complement each other.
APPLIED EXAMPLE
Put it in context
A fictional company identifies a vulnerable application reachable from the internet. It evaluates exposure and business impact, applies an approved mitigation, schedules remediation and verifies the result.
Illustrative scenario for learning, not a claim about a verified customer incident.Common mistakes
- Ranking only by a headline score
- Ignoring exposure and business impact
- Treating a workaround as permanent without review
Your practical checklist
Checklist ticks are temporary and are not recorded as account progress.
MINI RECAP
Prioritise with context, record temporary mitigations and verify that the weakness has actually been addressed.