The correct choice is the finding that the web server is running a version of Apache with a known RCE flaw. A vulnerability is a weakness or flaw in a system that a threat can exploit. In this scenario, the outdated Apache software is the weakness. The active targeting by organized crime groups represents a threat-an agent or event with the potential to cause harm. The potential exposure of customer records and reputational damage describes the impact. Finally, the correctly configured firewall is a security control, which is a safeguard implemented to protect an asset.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is a Remote Code Execution (RCE) vulnerability?
Open an interactive chat with Bash
How is a 'threat' different from a 'vulnerability'?
Open an interactive chat with Bash
Why is a correctly configured firewall not considered a vulnerability?