Cisco Certified Network Associate (CCNA) 200-301 · Free study guide
Objective 5.1 — Relate threats, vulnerabilities, exploits, and mitigations
Security analysis starts with precise language. A threat is a circumstance or actor capable of causing harm. A vulnerability is a weakness that could be used. An exploit is the technique or action that takes advantage of a vulnerability. A mitigation lowers likelihood or impact. Risk combines the chance of a harmful event with its consequence in a particular environment.
Build the causal chain
Start with the asset and the outcome that matters. Then identify a threat, the weakness it could reach, and the path by which that weakness might be exploited. Only then select a control. This avoids buying a generic security product without knowing what failure it is supposed to prevent.
Suppose a branch router still permits an old management protocol from any source. The router configuration is the asset. Credential interception is a possible harmful outcome, an on-path attacker is a threat actor, clear-text transport and unrestricted source access are vulnerabilities, and capturing a login is an exploit path. SSH, management ACLs, unique credentials, and alerting are complementary mitigations.
Separate likelihood from impact
A rarely exposed weakness protecting a critical route processor may still have high impact. A frequently scanned guest service may have high likelihood but a smaller contained impact. Segmentation can reduce blast radius even if it does not remove the original weakness. Backups and recovery procedures reduce impact but do not prevent an initial compromise.
Controls also have assumptions. A firewall rule depends on correct placement and direction. Multifactor authentication depends on independent factors and a safe recovery flow. Patching depends on inventory and verification. Treat a control as a risk reduction with evidence, not as a declaration that risk is zero.
Worked scenario
A public meeting-room jack reaches an internal user VLAN. Unauthorized physical access is the threat condition. The active unrestricted switchport is the vulnerability. Connecting a device and probing internal services is an exploit path. Disabling unused ports, placing active guest ports in an isolated VLAN, using identity-based access, and monitoring new attachments form a layered mitigation. Locking the wiring closet helps, but it does not address the exposed jack by itself.
Verification evidence
Document the asset, trust boundary, threat, vulnerability, plausible exploit, selected control, control owner, and remaining risk. Test that the control blocks the defined abuse case while preserving required traffic. Review logs, configuration state, patch level, and recovery capability. A control that was configured but never observed under test is only an assumption.
Common traps
- Calling every adverse event a vulnerability.
- Treating a mitigation as proof that exploitation is impossible.
- Ignoring physical or human paths because network controls exist.
- Measuring only likelihood while overlooking business impact.
- Naming a product without connecting it to a specific risk.
Readiness checklist
- I can distinguish threat, vulnerability, exploit, mitigation, and risk.
- I can trace an asset-centered causal chain.
- I can explain preventive, detective, and recovery controls.
- I can identify residual risk and verification evidence.
Practice and apply this objective
A free ExamOps account includes guided hands-on labs plus 10 practice questions per day shared across live tracks, with a written explanation on every question. No card required.
Start practicing free