nerdexam
CompTIA

SY0-501 · Question #230

Which of the following vulnerability types would the type of hacker known as a script kiddie be MOST dangerous against?

The correct answer is B. Unpatched exploitable Internet-facing services. Script kiddies primarily utilize automated tools and pre-existing exploits, making them most dangerous against unpatched, Internet-facing services that have known, readily exploitable vulnerabilities.

Submitted by paula_co· Mar 4, 2026Threats, vulnerabilities, and mitigations

Question

Which of the following vulnerability types would the type of hacker known as a script kiddie be MOST dangerous against?

Options

  • APasswords written on the bottom of a keyboard
  • BUnpatched exploitable Internet-facing services
  • CUnencrypted backup tapes
  • DMisplaced hardware token

How the community answered

(36 responses)
  • A
    3% (1)
  • B
    75% (27)
  • C
    6% (2)
  • D
    17% (6)

Why each option

Script kiddies primarily utilize automated tools and pre-existing exploits, making them most dangerous against unpatched, Internet-facing services that have known, readily exploitable vulnerabilities.

APasswords written on the bottom of a keyboard

Passwords written on the bottom of a keyboard constitute a physical security vulnerability, which falls outside the typical remote, tool-based attack methods employed by script kiddies.

BUnpatched exploitable Internet-facing servicesCorrect

Script kiddies are characterized by their reliance on readily available, automated tools and publicly documented exploit scripts to target known vulnerabilities. Unpatched Internet-facing services are prime targets because they are discoverable and often have existing exploits that these automated tools can easily leverage without requiring a deep understanding of the underlying systems or vulnerabilities.

CUnencrypted backup tapes

Unencrypted backup tapes represent a data at rest vulnerability usually exploited via physical access or insider threat, not the remote software exploits commonly used by script kiddies.

DMisplaced hardware token

A misplaced hardware token is a physical security or authentication issue that requires physical access or social engineering, which are not characteristic attack vectors for script kiddies.

Concept tested: Script kiddie attack methods and common targets

Source: https://learn.microsoft.com/en-us/windows/security/threat-protection/microsoft-defender-vulnerability-management/overview-mdvm

Topics

#threat actors#script kiddie#unpatched vulnerabilities#Internet-facing services

Community Discussion

No community discussion yet for this question.

Full SY0-501 Practice