CISSP Exam QuestionsBrowse all questions from this exam

CISSP Exam - Question 351


Commercial off-the-shelf (COTS) software presents which of the following additional security concerns?

Show Answer
Correct Answer: D

One significant security concern of commercial off-the-shelf (COTS) software is that exploits for this type of software are often well documented and publicly available. This makes it easier for malicious actors to find and use vulnerabilities in COTS software, posing a significant risk. While vendors can mitigate some risks through updates and patches, the fact that vulnerabilities are more likely to be known and accessible increases the security concern for users of COTS software.

Discussion

5 comments
Sign in to comment
CuteRabbit168Option: D
Sep 30, 2022

"COTS applications are much more easily available in the black hat community. Information such as vulnerabilities and various attack patterns are freely discussed and plotted to someone’s gain, which is a huge security risk for customers of the product." https://www.infosectrain.com/blog/security-in-cots-software-in-sdlc/

jackdryan
May 14, 2023

D is correct

krasskoOption: C
Sep 26, 2022

From CISSP student guide 6th edition: "...COTS software can mean that security is too generic or just simply doesn't exist". bdw, I think it's the best book to study but very difficult to get it.

Delab202
Dec 29, 2022

On the other hand, you don't always know how securely COTS products were developed or whether the vendor would use its flaws against you. There’s also the question of what happens when the vendor discontinues updates and support. For these reasons, you must evaluate COTS vendors as a supply chain security issue.

franbarproOption: D
Oct 26, 2022

Think about the dark web.... or hacking forums.

klarakOption: D
May 6, 2024

D is a gimme. Most of these are strengths of COTS or just incorrect.