Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsMedium

A security auditor is reviewing an organization's cloud infrastructure. The auditor discovers that several virtual machines (VMs) running critical services have public IP addresses and are directly exposed to the internet. Furthermore, the firewall rules for these VMs permit all incoming traffic on common ports, including HTTP, HTTPS, SSH, and RDP, from any source IP address. Which common security vulnerability does this scenario primarily represent?

  1. AInsecure Deserialization
  2. BInsufficient Logging and Monitoring
  3. CSecurity Misconfiguration
  4. DBroken Access Control
Show answer & explanation

Correct answer: C. Security Misconfiguration

The scenario describes explicitly exposed VMs with overly permissive firewall rules, which are classic examples of security misconfiguration. This vulnerability arises from improper setup or default configurations that leave systems open to attack.

Why the other options are wrong

  • A. Insecure deserialization is a specific application vulnerability, not general network exposure.
  • B. Insufficient logging/monitoring is about visibility, not direct exposure.
  • D. Broken access control relates to improper authorization, not network exposure.

Security Misconfiguration

A common vulnerability where security controls are improperly implemented, left at default settings, or not updated, leading to exploitable weaknesses in systems, applications, or networks. This can include open ports, default credentials, exposed directories, or incorrect permissions.

  • Often results from hasty deployment or lack of security hardening.
  • Includes default configurations, incomplete configurations, or unnecessary features.
  • Can lead to unauthorized access, data breaches, or system compromise.

Memory trick: Misconfiguration is like forgetting to lock the door or leaving the key under the mat.

More Security Concepts questions