CAS-002 · Question #826
A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?
The correct answer is B. Commercially available software packages are often widely available. Information concerning. Commercially available software packages introduce security risk because their vulnerabilities are publicly documented, giving attackers ready access to exploit information targeting widely deployed products.
Question
A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?
Options
- ACommercially available software packages are typically well known and widely available.
- BCommercially available software packages are often widely available. Information concerning
- CCommercially available software packages are not widespread and are only available in limited
- DCommercially available software packages are well known and widely available. Information
How the community answered
(44 responses)- B93% (41)
- C2% (1)
- D5% (2)
Why each option
Commercially available software packages introduce security risk because their vulnerabilities are publicly documented, giving attackers ready access to exploit information targeting widely deployed products.
Option A notes that commercial software is well known and widely available but does not address the critical risk factor - that vulnerability and exploit information is publicly accessible to attackers.
Because commercial off-the-shelf software is widely deployed, attackers actively research and publish vulnerability information through CVE databases, vendor advisories, and exploit frameworks. This publicly available vulnerability intelligence lowers the bar for attackers to target organizations using these products at scale. In contrast, custom-developed internal software is less likely to have known, documented exploits circulating in the attacker community.
Commercial software packages are by definition widespread and widely available, making this statement factually incorrect.
Option D overlaps with option B in content but is a distractor that does not as precisely capture the specific risk mechanism introduced by publicly available vulnerability details.
Concept tested: Security risks of commercial off-the-shelf software
Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final
Topics
Community Discussion
No community discussion yet for this question.