312-85 · Question #23
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
The correct answer is B. Zero-day attack. Zero-day attacks (B) exploit vulnerabilities that are unknown to the software vendor or for which no patch yet exists - the name comes from the fact that developers have had "zero days" to fix the flaw before it's weaponized. Why the distractors are wrong: A (Active online…
Question
In which of the following attacks does the attacker exploit vulnerabilities in a computer application before the software developer can release a patch for them?
Options
- AActive online attack
- BZero-day attack
- CDistributed network attack
- DAdvanced persistent attack
How the community answered
(32 responses)- A3% (1)
- B94% (30)
- D3% (1)
Explanation
Zero-day attacks (B) exploit vulnerabilities that are unknown to the software vendor or for which no patch yet exists - the name comes from the fact that developers have had "zero days" to fix the flaw before it's weaponized.
Why the distractors are wrong:
- A (Active online attack) is a broad category describing attacks that happen in real time against live systems (e.g., password cracking, session hijacking) - it says nothing about patch status or unknown vulnerabilities.
- C (Distributed network attack) refers to attacks that leverage multiple systems across a network (like DDoS), focusing on scale rather than exploiting unpatched flaws.
- D (Advanced persistent attack/APT) describes long-term, stealthy intrusions - often nation-state-sponsored - focused on maintaining access over time, not specifically on unpatched vulnerabilities.
Memory tip: Think of "zero-day" as a countdown that never started - the vendor has had zero days to respond because they don't even know the vulnerability exists yet.
Topics
Community Discussion
No community discussion yet for this question.