312-50V13 · Question #522
In the process of implementing a network vulnerability assessment strategy for a tech company, the security analyst is confronted with the following scenarios: 1) A legacy application is discovered…
The correct answer is D. Vulnerability scanning software is not immune to software engineering flaws that might lead to. Explanation Option D is correct because vulnerability scanning software itself can contain software engineering flaws, bugs, or coding errors that may cause it to miss vulnerabilities, produce false results, or even introduce new security issues - this is especially critical…
Question
Options
- AVulnerability scanning software is limited in its ability to perform live tests on web applications to
- BVulnerability scanning software cannot define the impact of an identified vulnerability on different
- CVulnerability scanning software is limited in its ability to detect vulnerabilities at a given point in
- DVulnerability scanning software is not immune to software engineering flaws that might lead to
How the community answered
(60 responses)- A7% (4)
- B5% (3)
- C18% (11)
- D70% (42)
Explanation
Explanation
Option D is correct because vulnerability scanning software itself can contain software engineering flaws, bugs, or coding errors that may cause it to miss vulnerabilities, produce false results, or even introduce new security issues - this is especially critical given the four scenarios described, where multiple complex vulnerability types (legacy software, outdated browsers, default configurations, and insecure protocols) require accurate detection across different contexts. A flawed scanning tool could provide a false sense of security across all four scenarios simultaneously.
Why the distractors are wrong:
- Option A is incorrect because many modern vulnerability scanners can perform live tests on web applications, so this is not the most significant limitation in this context.
- Option B is incorrect because while impact assessment has nuances, most vulnerability scanners do provide severity ratings and impact classifications, making this a lesser concern.
- Option C is incorrect because while point-in-time scanning is a real limitation, it doesn't directly threaten the accuracy of results the way software flaws do across all four described scenarios.
Memory Tip: Think of it this way - "Who watches the watchman?" If the security tool itself is flawed, no scenario is safe, making tool reliability the most fundamental concern. Remember: D = Defective tool = Danger to everything.
Topics
Community Discussion
No community discussion yet for this question.