Study. uk . com
  1. Home
  2. All questions
  3. Question 161

CompTIA Security+ study material · question 161 of 611

Why do vulnerable and outdated components form a category distinct from the rest of the OWASP Top Ten?

  1. Because they can only affect open-source software
  2. Because the flaw is inherited from a dependency rather than written by the team
  3. Because they are excluded from CVSS scoring
  4. Because they are always remotely exploitable
Show the answer

Answer: B. Because the flaw is inherited from a dependency rather than written by the team

Nothing in the team's own code is wrong, so code review will not find it; dependency inventory and updating will.

Source: OWASP Top 10 (OWASP) — OWASP Top Ten › Vulnerable and Outdated Components

Challenge yourself on this topic → Study as cards