SY0-701 · Question #621
An engineer has ensured that the switches are using the latest OS, the servers have the latest patches, and the endpoints' definitions are up to date. Which of the following will these actions most…
The correct answer is D. Known exploits. Keeping operating systems, patches, and endpoint definitions current directly addresses known exploits - vulnerabilities that have already been discovered, documented, and assigned fixes by vendors. These updates are specifically designed to close security gaps that attackers…
Question
An engineer has ensured that the switches are using the latest OS, the servers have the latest patches, and the endpoints' definitions are up to date. Which of the following will these actions most effectively prevent?
Options
- AZero-day attacks
- BInsider threats
- CEnd-of-life support
- DKnown exploits
How the community answered
(42 responses)- A2% (1)
- B2% (1)
- C7% (3)
- D88% (37)
Explanation
Keeping operating systems, patches, and endpoint definitions current directly addresses known exploits - vulnerabilities that have already been discovered, documented, and assigned fixes by vendors. These updates are specifically designed to close security gaps that attackers are actively targeting with existing techniques.
Why the distractors are wrong:
- A (Zero-day attacks): Zero-days are unknown vulnerabilities with no existing patch, so even fully updated systems remain vulnerable to them by definition.
- B (Insider threats): Patching and updates address technical vulnerabilities, not malicious or negligent behavior by trusted users - that requires access controls and monitoring.
- C (End-of-life support): EoL is a status (vendor no longer provides updates), not a threat category you "prevent" through patching - in fact, EoL systems can't receive the patches described here.
Memory tip: Think of patches as "plugging known holes in a fence." If someone has already published a map of the holes (known exploits), patching covers them. But if someone finds a brand-new hole nobody knows about yet (zero-day), your patching routine can't help.
Topics
Community Discussion
No community discussion yet for this question.