Cisco CyberOps Associate (CBROPS) 200-201Security ConceptsEasy

A security auditor is reviewing an organization's cloud environment. The auditor identifies that several virtual machines (VMs) are configured with default administrative credentials and are directly exposed to the internet with unnecessary open ports. Which security vulnerability category does this scenario primarily represent?

  1. ABroken Access Control
  2. BInsufficient Logging & Monitoring
  3. CInjection Flaws
  4. DSecurity Misconfiguration
Show answer & explanation

Correct answer: D. Security Misconfiguration

The scenario describes issues like default credentials and unnecessary open ports, which are classic examples of improper configuration of systems and services. This falls directly under the category of Security Misconfiguration.

Why the other options are wrong

  • A. Broken Access Control relates to improper permissions or authorization, not default settings.
  • B. Insufficient Logging & Monitoring is about the absence or inadequacy of security event collection and analysis.
  • C. Injection Flaws involve sending untrusted data to an interpreter, often seen in web applications.

Security Misconfiguration

A common security vulnerability arising from insecure default configurations, incomplete or ad hoc configurations, open cloud storage, or improperly configured HTTP headers.

  • Often results from lax security practices or oversight.
  • Can expose systems and data to unauthorized access.
  • Includes default credentials, unnecessary open ports, and unpatched software.
  • Is a preventable vulnerability through proper hardening and review.

Memory trick: Configuration Flaws Expose Systems

More Security Concepts questions