210-250 · Question #6
Which definition of vulnerability is true?
The correct answer is A. an exploitable unpatched and unmitigated weakness in software. A vulnerability is a specific exploitable weakness in software that has not been patched or mitigated, which an attacker can leverage to compromise a system.
Question
Which definition of vulnerability is true?
Options
- Aan exploitable unpatched and unmitigated weakness in software
- Ban incompatible piece of software
- Csoftware that does not have the most current patch applied
- Dsoftware that was not approved for installation
How the community answered
(60 responses)- A92% (55)
- B2% (1)
- C5% (3)
- D2% (1)
Why each option
A vulnerability is a specific exploitable weakness in software that has not been patched or mitigated, which an attacker can leverage to compromise a system.
By definition, a vulnerability is a weakness or flaw in software, hardware, or configuration that can be exploited by a threat actor to gain unauthorized access or cause harm. The key qualifiers are that it is exploitable and unmitigated - meaning no patch, workaround, or compensating control has been applied. This aligns with the NIST definition used across security frameworks.
Incompatible software describes a functionality or integration problem, not a security weakness that can be exploited.
Software lacking the most current patch is a condition that may expose a vulnerability, but the vulnerability itself is the underlying weakness, not the absence of a patch.
Unapproved software is a policy compliance issue, not a technical security vulnerability by definition.
Concept tested: Definition of vulnerability in cybersecurity
Source: https://nvd.nist.gov/vuln
Topics
Community Discussion
No community discussion yet for this question.