Study. uk . com
  1. Home
  2. All questions
  3. Question 190

CISM study material · question 190 of 1000

An organisation runs no database management system anywhere in its estate. What does SP 800-30 say about its exposure to SQL injection?

  1. Susceptibility can only be determined by scanning
  2. It remains exposed because the threat exists in the wild
  3. It is not susceptible, because no threat can exploit a vulnerability it does not have
  4. It must still record the risk and accept it formally
Show the answer

Answer: C. It is not susceptible, because no threat can exploit a vulnerability it does not have

SP 800-30 makes susceptibility conditional on the vulnerability existing: with no database management system there is nothing for SQL injection to exploit, and the guide uses that very case.

Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Predisposing Conditions

Challenge yourself on this topic → Study as cards