nerdexam
Cisco

100-160 · Question #20

Which vulnerabilities can a risk assessment reveal? (Choose two)

The correct answer is A. Outdated software C. Misconfigured access controls. A risk assessment identifies security weaknesses in systems, processes, and configurations - making outdated software (A) and misconfigured access controls (C) the correct answers, as both represent exploitable vulnerabilities that a security review would uncover and document…

Threats and Vulnerabilities

Question

Which vulnerabilities can a risk assessment reveal? (Choose two)

Options

  • AOutdated software
  • BExcessive packet loss
  • CMisconfigured access controls
  • DInsufficient power supply

How the community answered

(22 responses)
  • A
    86% (19)
  • B
    9% (2)
  • D
    5% (1)

Explanation

A risk assessment identifies security weaknesses in systems, processes, and configurations - making outdated software (A) and misconfigured access controls (C) the correct answers, as both represent exploitable vulnerabilities that a security review would uncover and document.

Why the distractors are wrong:

  • B (Excessive packet loss) is a network performance issue, not a security vulnerability - it belongs in availability monitoring or network diagnostics, not a risk assessment.
  • D (Insufficient power supply) is an infrastructure/operational concern related to availability, not a vulnerability in the security sense a risk assessment targets.

Memory tip: Think "CAMP" - risk assessments find things attackers can Compromise (Access controls) and Malware can exploit (outdated software with Patches missing). Power and packet loss are operational metrics, not attack surfaces.

Topics

#Risk assessment#Vulnerabilities#Software patching#Access controls

Community Discussion

No community discussion yet for this question.

Full 100-160 Practice