From the course: ISC2 Systems Security Certified Practitioner (SSCP) (2024) Cert Prep

Unlock this course with a free trial

Join today to access over 24,600 courses taught by industry experts.

Zero-days and the Advanced Persistent Threat

Zero-days and the Advanced Persistent Threat

- [Instructor] Many attacks take place when an organization fails to apply security patches, leaving themselves vulnerable to an attacker who knows how to exploit the missing patch. The fix for that situation is simple. Organizations should apply security updates as soon as they are available from operating system and application vendors to fortify their systems against attack. Unfortunately, it's not always possible to protect yourself from every possible vulnerability, because not all of them are known. Consider for example that modern operating systems contain literally millions of lines of code. There's no doubt that lurking somewhere in that massive amount of code are new security vulnerabilities that the security community simply hasn't discovered yet. Those vulnerabilities can expose an organization to risk. When a security researcher discovers a new vulnerability, they typically handle it in an ethical and…

Contents