nerdexam
CompTIA

CAS-002 · Question #826

A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?

The correct answer is B. Commercially available software packages are often widely available. Information concerning. Commercially available software packages introduce security risk because their vulnerabilities are publicly documented, giving attackers ready access to exploit information targeting widely deployed products.

Enterprise Security

Question

A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?

Options

  • ACommercially available software packages are typically well known and widely available.
  • BCommercially available software packages are often widely available. Information concerning
  • CCommercially available software packages are not widespread and are only available in limited
  • DCommercially available software packages are well known and widely available. Information

How the community answered

(44 responses)
  • B
    93% (41)
  • C
    2% (1)
  • D
    5% (2)

Why each option

Commercially available software packages introduce security risk because their vulnerabilities are publicly documented, giving attackers ready access to exploit information targeting widely deployed products.

ACommercially available software packages are typically well known and widely available.

Option A notes that commercial software is well known and widely available but does not address the critical risk factor - that vulnerability and exploit information is publicly accessible to attackers.

BCommercially available software packages are often widely available. Information concerningCorrect

Because commercial off-the-shelf software is widely deployed, attackers actively research and publish vulnerability information through CVE databases, vendor advisories, and exploit frameworks. This publicly available vulnerability intelligence lowers the bar for attackers to target organizations using these products at scale. In contrast, custom-developed internal software is less likely to have known, documented exploits circulating in the attacker community.

CCommercially available software packages are not widespread and are only available in limited

Commercial software packages are by definition widespread and widely available, making this statement factually incorrect.

DCommercially available software packages are well known and widely available. Information

Option D overlaps with option B in content but is a distractor that does not as precisely capture the specific risk mechanism introduced by publicly available vulnerability details.

Concept tested: Security risks of commercial off-the-shelf software

Source: https://csrc.nist.gov/publications/detail/sp/800-64/rev-2/final

Topics

#COTS software#software vulnerabilities#security risk#vendor software

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice