exam questions

Exam 200-201 All Questions

View all questions & answers for the 200-201 exam

Exam 200-201 topic 1 question 29 discussion

Actual exam question from Cisco's 200-201
Question #: 29
Topic #: 1
[All 200-201 Questions]

What is the difference between an attack vector and an attack surface?

  • A. An attack surface identifies vulnerabilities that require user input or validation; and an attack vector identifies vulnerabilities that are independent of user actions.
  • B. An attack vector identifies components that can be exploited; and an attack surface identifies the potential path an attack can take to penetrate the network.
  • C. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
  • D. An attack vector identifies the potential outcomes of an attack; and an attack surface launches an attack using several methods against the identified vulnerabilities.
Show Suggested Answer Hide Answer
Suggested Answer: C 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
036e554
10 months ago
ANS: C Attack Vector refers to specific path uses to gain unauthorized access to a system or network, while An attack surface recognizes which network parts are vulnerable to an attack.
upvoted 1 times
...
WISDOM2080
1 year, 7 months ago
C. An attack surface recognizes which network parts are vulnerable to an attack; and an attack vector identifies which attacks are possible with these vulnerabilities.
upvoted 1 times
...
alhamry
1 year, 11 months ago
Option C is partially correct, as it correctly defines an attack surface as recognizing which network parts are vulnerable to an attack. However, it does not accurately define an attack vector. An attack vector is not just about identifying which attacks are possible with the vulnerabilities, but it also identifies the specific method or path used to exploit the vulnerability. Option B is the best answer, as it correctly defines an attack vector as identifying the components that can be exploited and an attack surface as identifying the potential path an attack can take to penetrate the network.
upvoted 1 times
...
drdecker100
2 years, 2 months ago
Selected Answer: C
An attack surface represents the overall set of vulnerabilities that an attacker could potentially exploit to launch an attack. This can include hardware, software, network protocols, configurations, and user accounts. By identifying and assessing the attack surface, defenders can understand the overall security posture of their system or network and take steps to reduce its exposure to potential attacks. An attack vector, on the other hand, refers to the specific method or path that an attacker uses to exploit a particular vulnerability within the attack surface. An attacker may use multiple attack vectors to reach their goal, such as social engineering, malware, or exploiting a specific software flaw.
upvoted 4 times
...
SecurityGuy
2 years, 5 months ago
Selected Answer: C
Attack Vector, Attack Surface and Threat Vector Vector - It is a quantity having direction as well as magnitude Attack Vector - is a “method” of gaining unauthorized access to a network or computer system. It takes many forms such as malware, ransomware, compromised credentials, phishing, web pages, pop-ups etc; basically any method that intends to compromise a system. Attack Surface - is the total number of attack vectors an attacker can use to manipulate or compromise a network or system. Can also be defined as the total number of possible methods to attack a network or system. Threat Vector - can be used interchangeably with attack vector and generally describes the potential ways a hacker can gain access to data or other confidential information. https://www.upguard.com/blog/attack-vector#:~:text=minimize%20cybersecurity%20risk.-,What%20is%20the%20Difference%20Between%20an%20Attack%20Vector%2C%20Attack%20Surface,computer%20system%20or%20extract%20data.
upvoted 1 times
...
kyle942
2 years, 7 months ago
The 17 most common attack vectors are: Compromised Credentials Weak Credentials Uneducated Employees Insider Threats Poor Encryption Unpatched Software Security Vulnerabilities Third-party Vendors Phishing Attacks Ransomware Brute Force Attacks Distributed Denial of Service (DDoS) Attacks SQL Injections Trojans Session Hijacking Cross-Site Scripting (XSS) Man-in-the-Middle Attacks
upvoted 2 times
...
[Removed]
2 years, 7 months ago
Selected Answer: C
C is better answer but B is also correct right?
upvoted 1 times
...
halamah
3 years, 5 months ago
correct
upvoted 1 times
...
eggheadsv
3 years, 5 months ago
Correct Answer: C The attack surface of a software environment is the sum of the different points (for "attack vectors") where an unauthorized user (the "attacker") can try to enter data to or extract data from an environment.[1][2] Keeping the attack surface as small as possible is a basic security measure.[3] https://en.wikipedia.org/wiki/Attack_surface In computer security, an attack vector is a specific path, method, or scenario that can be exploited to break into an IT system, thus compromising its security. The term was derived from the corresponding notion of vector in biology. An attack vector may be exploited manually, automatically, or through a combination of manual and automatic activity. https://en.wikipedia.org/wiki/Attack_vector
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago