Palo Alto Networks Certified Network Security Administrator (PCNSA)Cybersecurity FundamentalsMedium
A cybersecurity incident response team is analyzing a recent breach where an attacker exploited a previously unknown vulnerability in a proprietary web application. This vulnerability had no public advisories or patches available at the time of the attack. Which type of vulnerability was exploited?
- ACross-Site Scripting (XSS)
- BBuffer Overflow
- CZero-Day
- DSQL Injection
Show answer & explanationAnswer & explanation
Correct answer: C. Zero-Day
A zero-day vulnerability is a software flaw that is unknown to the vendor or the public, meaning there are no patches or advisories available at the time it is exploited. The scenario explicitly states 'previously unknown vulnerability' and 'no public advisories or patches available'.
Why the other options are wrong
- A. Cross-Site Scripting (XSS) is a type of vulnerability, but not necessarily unknown or unpatched.
- B. Buffer overflow is a type of vulnerability, but not necessarily unknown or unpatched.
- D. SQL injection is a type of vulnerability, but not necessarily unknown or unpatched.
Zero-Day Vulnerability
A software vulnerability that is unknown to the vendor or the public at the time it is discovered and exploited by attackers, meaning no patch is available.
- Highly dangerous due to lack of defense.
- Exploited before a patch is released.
- Often used in targeted attacks.
Memory trick: The 'zero' in zero-day means zero time to patch before the attack.