exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 82 discussion

Actual exam question from Cisco's 200-201
Question #: 82
Topic #: 1
[All 200-201 Questions]

What is an attack surface as compared to a vulnerability?

  • A. any potential danger to an asset
  • B. the sum of all paths for data into and out of the environment
  • C. an exploitable weakness in a system or its design
  • D. the individuals who perform an attack
Show Suggested Answer Hide Answer
Suggested Answer: B 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
beowolf
Highly Voted 2 years, 7 months ago
B. is attack vector not attack surface. C is the correct answer. An attack surface is the total sum of vulnerabilities that can be exploited to carry out a security attack. Attack surfaces can be physical or digital. The term attack surface is often confused with the term attack vector, but they are not the same thing. The surface is what is being attacked; the vector is the means by which an intruder gains access.
upvoted 9 times
Jack_B
2 years, 5 months ago
Correct me if I am wrong, but this question is asking about attack surface. Hence, looking at the options available, I would simply eliminate option A because it is defined as a risk, option D because it is defined as a threat actor. Which leaves me with option B and C. Option C sounds more like describing a vulnerability which then leaves me with option B as the answer. Please do correct me if I am incorrect. Thank you.
upvoted 11 times
beowolf
2 years, 5 months ago
@Jack_B, the surface is what is being attacked so C should be correct, please see my comment above, let me know if you have any more info. cheers mate.
upvoted 1 times
beowolf
2 years, 5 months ago
From wikipedia, The attack surface of a software environment is the sum of the different points (for "attack vectors") where an unauthorized user (the "attacker") can try to enter data to or extract data from an environment.[1][2] [3]Keeping the attack surface as small as possible is a basic security measure. So as you said B is correct then, sorry for the confusion.
upvoted 12 times
...
...
...
...
tsabee
Highly Voted 2 years ago
My opinion: a - this is the Threat b - Correct Answer (only may be incorrect wording) c - Vulnerabilities d - Threat Actor According to the Cisco "Understanding Cisco Cybersecurity Operations Fundamentals" course the "B" should be the right answer. One of the test question in this topics: Q: What best describes an attack surface? A: The sum of the different points ("attack vectors") in a given computing device or network that are accessible to an unauthorized user ("attacker")
upvoted 7 times
...
Stevens0103
Most Recent 5 months, 1 week ago
Selected Answer: B
source: https://contenthub.netacad.com/legacy/CyberOps/1.1/en/index.html#6.1.1.1 Vulnerability and Attack Surface – A weakness in a system or its design that could be exploited by a threat. An attack surface is the total sum of the vulnerabilities in a given system that is accessible to an attacker. The attack surface describes different points where an attacker could get into a system, and where they could get data out of the system. For example, your operating system and web browser could both need security patches. They are each vulnerable to attacks. Together, they create an attack surface the threat actor can exploit.
upvoted 2 times
...
alhamry
5 months, 2 weeks ago
The best answer is "B. the sum of all paths for data into and out of the environment." An attack surface refers to the sum of all paths through which an attacker can gain access to a system or environment to carry out an attack. This includes not only the hardware and software components of the system but also the interfaces, networks, and protocols that allow data to enter and leave the system. A vulnerability, on the other hand, is an exploitable weakness or flaw in a system or its design that can be used by an attacker to compromise the system's security and gain unauthorized access. Vulnerabilities can exist in hardware, software, network configurations, or even in human behavior. In summary, while a vulnerability is a specific weakness or flaw that can be exploited by an attacker, an attack surface is the sum of all possible avenues an attacker can use to gain access to a system or environment and carry out an attack.
upvoted 2 times
...
drdecker100
8 months, 1 week ago
Selected Answer: B
B. Attack surface: The sum of all paths, entry points, and vulnerabilities through which an attacker can access an environment, system, or application.
upvoted 2 times
...
cy_analyst
1 year ago
Selected Answer: C
From the book CCNA cybersecurity Operations Companion Guide.: Recall that a vulnerability is a weakness in a system or its design that could be exploited by a threat. An attack surface is the total sum of the vulnerabilities in a given system that is accessible to an attacker. The attack surface can consist of open ports on servers or hosts, software that runs on Internet-facing servers, wireless network protocols, and even users.
upvoted 1 times
...
joseph267
1 year, 2 months ago
for me answer C seems to talk about 1 thing but option B talks abou many so I think B is the one here
upvoted 1 times
...
ivlis_27
1 year, 11 months ago
Selected Answer: B
because it's a surface
upvoted 3 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago