PCCET · Question #228
What is the definition of a zero-day threat?
The correct answer is B. The period between the discovery of a vulnerability and development and release of a patch. Option B is correct because a "zero-day" threat refers to the window of vulnerability that exists between the moment a flaw is discovered and when a patch is developed and released - during this period, attackers can exploit the flaw with zero days of defense available to…
Question
What is the definition of a zero-day threat?
Options
- AThe amount of time it takes to discover a vulnerability and release a security fix
- BThe period between the discovery of a vulnerability and development and release of a patch
- CThe day a software vendor becomes aware of an exploit and prevents any further hacking
- DA specific day during which zero threats occurred
How the community answered
(38 responses)- A5% (2)
- B89% (34)
- C3% (1)
- D3% (1)
Explanation
Option B is correct because a "zero-day" threat refers to the window of vulnerability that exists between the moment a flaw is discovered and when a patch is developed and released - during this period, attackers can exploit the flaw with zero days of defense available to defenders.
Why the distractors are wrong:
- A describes the overall patch lifecycle (discovery through fix), not the vulnerable gap itself - it conflates the timeline with the threat window.
- C is essentially fictional; vendors cannot unilaterally "prevent further hacking" simply by becoming aware of an exploit, and this framing inverts the risk (awareness doesn't equal protection).
- D is a literal misreading of "zero-day" - it has nothing to do with a calendar day of zero incidents.
Memory tip: Think of "zero-day" from the defender's perspective - they have zero days of warning or patch coverage. The threat exists precisely because the fix hasn't arrived yet. If there's already a patch, it's no longer a zero-day.
Topics
Community Discussion
No community discussion yet for this question.