問題文
A public-facing server runs a library version with a documented flaw. Working code that abuses the flaw was published last week, and a group known to target this industry has been seen using it. Which mapping of the four terms to this situation is correct?
選択肢
- The terms are ordered by how early each one appears in the timeline of an attack rather than by what each one describes, so the flaw is the threat, the group is the vulnerability, the published code is the risk, and the exploit is the exposure of the server.
- All four terms describe the same thing at different levels of detail, so the mapping does not affect the decision that has to be taken about the server.
- The flaw is the vulnerability, the published code is the exploit, the group is the threat, and the chance of loss given all three is the risk.
- The risk is fixed by the vendor patch, so no other term applies.