Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A cybersecurity incident response team is analyzing a recent breach where an attacker gained initial access by exploiting a vulnerability in a web application. The vulnerability was previously unknown to the software vendor and had no available patch at the time of the attack. What term best describes this type of vulnerability?
- AMisconfiguration
- BZero-day vulnerability
- CLogic flaw
- DKnown vulnerability
Show answer & explanationAnswer & explanation
Correct answer: B. Zero-day vulnerability
A zero-day vulnerability is a software flaw that is unknown to the vendor and for which no patch exists, making it a highly dangerous attack vector, precisely matching the scenario described.
Why the other options are wrong
- A. Misconfiguration refers to incorrect settings, not an inherent software flaw.
- C. A logic flaw is an error in the design of the application's functionality, but the key aspect here is the 'unknown to vendor, no patch' element.
- D. A known vulnerability would have been publicly disclosed and likely have a patch available.
Zero-day vulnerability
A software or hardware flaw that is unknown to the vendor and for which no official patch or fix has been released, making it a lucrative target for attackers.
- Exploited before the vendor is aware or has a patch.
- Highly dangerous due to lack of immediate defense.
- Often used in targeted attacks by sophisticated adversaries.
- Requires advanced detection methods like behavioral analysis.
Memory trick: Zero knowledge, zero days to patch.