N10-009 exam dumps

N10-009 practice question 255 of 329

Network+. Associate level, CompTIA. Free question with the correct answer and a full explanation.

N10-009 Question 255

Single answerCommon security terminology: Risk, Vulnerability, Exploit, Threat, Confidentiality, Integrity, and Availability (CIA) triad

A hospital's IT team discovers that several internet-facing file transfer servers are still using an outdated service with a known remote-code-execution flaw. No compromise has been confirmed, but the security team is concerned that attackers could use publicly available code to access patient records or disrupt the service. Which term BEST describes the outdated flaw on the servers?

  1. A

    Threat

  2. B

    Vulnerability

  3. C

    Exploit

  4. D

    Risk

  5. E

    Availability

Show answer and explanation

Correct answer: B

Explanation

The best answer is Vulnerability because the scenario identifies a specific weakness: an outdated internet-facing service with a known remote-code-execution flaw. In common security terminology, a threat is the actor or event that may cause harm, a vulnerability is the weakness, an exploit is the tool or technique used to take advantage of that weakness, and risk is the potential business or operational impact if that exploitation occurs. The CIA triad helps frame consequences: unauthorized access to patient records would affect confidentiality, unauthorized changes would affect integrity, and service disruption would affect availability. This aligns with standard security guidance from NIST, including terminology used in vulnerability management and risk assessment practices such as NIST SP 800-40 and NIST SP 800-61.

  • A. Incorrect.

    Incorrect. A threat is a potential source of harm, such as a cybercriminal, ransomware group, insider, or malicious activity capable of taking advantage of a weakness. In this scenario, the attackers are the threat, not the flaw itself.

  • B. Correct.

    Correct. A vulnerability is a weakness in hardware, software, configuration, or process that could be exploited. The outdated service with a known remote-code-execution flaw is the weakness present on the servers.

  • C. Incorrect.

    Incorrect. An exploit is the code, technique, or method used to take advantage of a vulnerability. The scenario mentions that publicly available code exists, which would be the exploit, but the question asks about the flaw on the servers.

  • D. Incorrect.

    Incorrect. Risk is the potential for loss or damage when a threat can exploit a vulnerability, often considered in terms of likelihood and impact. Here, the risk is that patient data could be exposed or the service disrupted, not the flaw itself.

  • E. Incorrect.

    Incorrect. Availability is one part of the CIA triad and refers to systems and data being accessible when needed. Service disruption would affect availability, but availability is not the term for the underlying software weakness.

Timed practice exam

Take a N10-009 practice test under exam conditions

90 questions in 90 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam