100-160 · Question #20
Which vulnerabilities can a risk assessment reveal? (Choose two)
The correct answer is A. Outdated software C. Misconfigured access controls. A risk assessment identifies security weaknesses in systems, processes, and configurations - making outdated software (A) and misconfigured access controls (C) the correct answers, as both represent exploitable vulnerabilities that a security review would uncover and document…
Question
Which vulnerabilities can a risk assessment reveal? (Choose two)
Options
- AOutdated software
- BExcessive packet loss
- CMisconfigured access controls
- DInsufficient power supply
How the community answered
(22 responses)- A86% (19)
- B9% (2)
- D5% (1)
Explanation
A risk assessment identifies security weaknesses in systems, processes, and configurations - making outdated software (A) and misconfigured access controls (C) the correct answers, as both represent exploitable vulnerabilities that a security review would uncover and document.
Why the distractors are wrong:
- B (Excessive packet loss) is a network performance issue, not a security vulnerability - it belongs in availability monitoring or network diagnostics, not a risk assessment.
- D (Insufficient power supply) is an infrastructure/operational concern related to availability, not a vulnerability in the security sense a risk assessment targets.
Memory tip: Think "CAMP" - risk assessments find things attackers can Compromise (Access controls) and Malware can exploit (outdated software with Patches missing). Power and packet loss are operational metrics, not attack surfaces.
Topics
Community Discussion
No community discussion yet for this question.