A company relies on open-source software libraries to build the software used by its customers. Which of the following vulnerability types would be the most difficult to remediate due to the company’s reliance on open-source libraries?
Choose an answer
Tap an option to check your answer.
Correct answer: Zero-day.
Why this is the answer
Zero-day vulnerabilities are the most difficult to remediate in open-source libraries because they are unknown to the vendor (the open-source community, in this case) and have no existing patch. The company would have to discover the vulnerability itself, develop a fix, and then contribute it back to the open-source project, or wait for the community to identify and patch it, which can take significant time. Buffer overflows, SQL injections, and cross-site scripting are well-known vulnerability types with established mitigation strategies and often readily available patches or workarounds. While they can be present in open-source libraries, the remediation process is generally more straightforward once identified, as the vulnerabilities themselves are not novel.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed