ITPEC IP April 2024 Question 35

Source exam: ITPEC IP April 2024Topic: Security

ITPEC IP April 2024 — Question 35 of 100

A zero-day attack exploits a software vulnerability before an effective countermeasure is publicly available or deployable. Defenders have had essentially zero days to prepare once exploitation becomes known. The vulnerability may be unknown to the vendor, or known but not yet fixed, leaving systems exposed until a patch, configuration mitigation, or detection method is available.

Answer (c)

Why not others:
- (a) zero-day does not mean an attack that stops a system within 24 hours

- (b) it does not refer to a virus without an incubation period

- (d) social engineering and eavesdropping are different attack methods and do not define zero-day exploitation

Key rule: The word day measures defender preparation time, not attack duration or symptom delay: a zero-day vulnerability is exploited before users have a ready fix.

AI-generated — may contain errors

The original exam layout is preserved in the image so diagrams, formulas, tables, and code remain accurate.

This question comes from an official ITPEC past paper. ITPEC Practice is an independent study tool and is not affiliated with ITPEC. See the official IP past-paper collection or Report an issue.