112-52 · Question #3
Which of the following best describes a zero-day vulnerability?
The correct answer is A. A vulnerability that is exploited before the vendor has issued a patch. Option A is correct because a zero-day vulnerability refers to a flaw that is actively exploited "on day zero" - meaning before the vendor knows about it or has had any time (zero days) to develop and release a patch, leaving defenders with no ready fix. Option B is wrong because
Question
Which of the following best describes a zero-day vulnerability?
Options
- AA vulnerability that is exploited before the vendor has issued a patch
- BA vulnerability that affects all versions of a software
- CA vulnerability that exists for zero days before being detected
- DA vulnerability that does not require user interaction to be exploited
How the community answered
(19 responses)- A89% (17)
- B5% (1)
- C5% (1)
Explanation
Option A is correct because a zero-day vulnerability refers to a flaw that is actively exploited "on day zero" - meaning before the vendor knows about it or has had any time (zero days) to develop and release a patch, leaving defenders with no ready fix.
Option B is wrong because a vulnerability doesn't need to affect all versions to be zero-day - scope of impact is unrelated to the concept. Option C inverts the meaning: zero-day vulnerabilities often persist for months or years before detection; the "zero" refers to patch availability, not detection time. Option D describes a wormable or zero-click vulnerability, which is a separate classification entirely.
Memory tip: Think of "zero days" as the vendor having zero days of warning - the attacker strikes before any defense exists.
Topics
Community Discussion
No community discussion yet for this question.