nerdexam
CompTIA

CAS-003 · Question #165

A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?

The correct answer is B. Commercially available software packages are often widely available. Information concerning. Commercially available software packages are often widely available. Huge companies like Microsoft develop software packages that are widely available and in use on most computers. Most companies that develop commercial software make their software available through many…

Risk Management

Question

A company decides to purchase commercially available software packages. This can introduce new security risks to the network. Which of the following is the BEST description of why this is true?

Options

  • ACommercially available software packages are typically well known and widely available.
  • BCommercially available software packages are often widely available. Information concerning
  • CCommercially available software packages are not widespread and are only available in limited
  • DCommercially available software packages are well known and widely available. Information

How the community answered

(59 responses)
  • A
    8% (5)
  • B
    86% (51)
  • C
    3% (2)
  • D
    2% (1)

Explanation

Commercially available software packages are often widely available. Huge companies like Microsoft develop software packages that are widely available and in use on most computers. Most companies that develop commercial software make their software available through many commercial outlets (computer stores, online stores etc). Information concerning vulnerabilities is often kept internal to the company that developed the software. The large companies that develop commercial software packages are accountable for the software. Information concerning vulnerabilities being made available could have a huge financial cost to the company in terms of loss of reputation and lost revenues. Information concerning vulnerabilities is often kept internal to the company at least until a patch is available to fix the vulnerability.

Topics

#commercial software risk#known vulnerabilities#software supply chain#patch exposure

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice