- Home
- All questions
- Question 190
CISM study material · question 190 of 1000
An organisation runs no database management system anywhere in its estate. What does SP 800-30 say about its exposure to SQL injection?
Show the answer
Answer: C. It is not susceptible, because no threat can exploit a vulnerability it does not have
SP 800-30 makes susceptibility conditional on the vulnerability existing: with no database management system there is nothing for SQL injection to exploit, and the guide uses that very case.
Source: NIST SP 800-30 Rev. 1 (NIST) — Sec. 2.3.1 Risk Models — Predisposing Conditions