200-201 Question 20
Single answerWhile investigating a potential security breach, an analyst notices that an unauthorized individual accessed sensitive data by exploiting a vulnerability in a company's web application. Which security term best describes this unauthorized access?
- A
Threat
- B
Vulnerability
- C
Exploit
- D
Risk
Show answer and explanation
Correct answer: C
Explanation
The term 'exploit' is used to describe the act of taking advantage of a vulnerability to achieve unauthorized access or perform malicious actions. In the given scenario, the unauthorized individual accessed sensitive data by exploiting a vulnerability in the company's web application, making 'exploit' the most accurate term for this context.
- A. Incorrect.
A threat refers to anything that can exploit a vulnerability, intentionally or accidentally, and cause harm to an asset or organization. In this scenario, the threat would be the unauthorized individual or malicious actor.
- B. Incorrect.
A vulnerability is a weakness in a system, such as a web application, that could be exploited to gain unauthorized access. While the scenario mentions a vulnerability, this option does not best describe the act of unauthorized access.
- C. Correct.
An exploit is the specific method or technique used to take advantage of a vulnerability. In this case, the unauthorized individual exploited the web application's vulnerability to access sensitive data.
- D. Incorrect.
Risk represents the potential for loss or harm when a threat exploits a vulnerability. While risk is present in this scenario, it does not specifically describe the unauthorized access event.