Free CompTIA Security Plus SY0-701 Actual Exam Questions - Question 13 Discussion
system vulnerabilities?
A/C? C seems off since env vars rarely set crypto standards directly, but A highlights how env vars can change how bad a vulnerability gets, which feels more on point here.
I’m thinking B might be plausible too—if attackers can overwrite env vars in memory, that could be a direct vector for malicious code. Is that less likely than the impact scope idea in A?
A. It’s about how these variables can change how big or bad an exploit becomes, not necessarily the technical details like in B or C. D seems off since updates aren’t usually tied to env vars like that.
B/C? B makes sense since overwriting variables could help attackers inject code, but C also seems plausible if environment variables dictate crypto standards. Not sure which one fits better here.
A, because environment variables impact vulnerability scope directly.