Skip to main content
Offline·Progress is saved on this device and syncs the next time you open the app online.
Compare

Vulnerability vs Threat vs Risk

These three terms are the vocabulary of risk management, and the exam expects you to tell them apart precisely. A threat exploits a vulnerability, and the resulting exposure is risk.

Last updated August 2026

Vulnerability vs Threat vs Risk side by side
AspectVulnerabilityThreatRisk
DefinitionA weakness that could be exploitedSomething or someone that could exploit a weaknessThe likelihood and impact of a threat exploiting a vulnerability
NatureA condition (state of the asset)An actor or event (the danger)A calculation (likelihood times impact)
ExampleUnpatched server, weak passwordA hacker, malware, a flood, a careless userThe chance and cost of data loss if the flaw is exploited
Can you remove it?Reduce it by patching and hardeningUsually cannot remove the threat itselfManage it: avoid, transfer, mitigate, or accept
QuestionWhat is weak?What could go wrong?How likely, and how bad?

The bottom line

A threat is the danger, a vulnerability is the weakness it targets, and risk is the likelihood and impact if the two meet. Roughly, risk equals threat times vulnerability times impact. You cannot stop threats from existing, but you can reduce vulnerabilities and manage risk.

Lock it in with practice

Reading the difference is a start. SecPlus Mastery drills it with over 1,000 practice questions, timed mock exams, and spaced review across all five SY0-701 domains, so it sticks for exam day.

New accounts get 30% off both plans for 7 days: the 90-Day Pass is $27.30 instead of $39.

FAQ

  • What is the relationship between vulnerability, threat, and risk?
    A threat is the danger, a vulnerability is the weakness it targets, and risk is the likelihood and impact if the threat exploits the vulnerability. Remove the vulnerability and the same threat carries far less risk.
  • What are the ways to respond to risk?
    The four classic responses are accept, avoid, transfer (for example, insurance), and mitigate (apply controls to reduce likelihood or impact).

More Security+ comparisons

Compare Security+ to other certifications

Written to the CompTIA Security+ SY0-701 objectives. CompTIA and Security+ are trademarks of CompTIA, used here for identification only.