easyMultiple ChoiceObjective-mapped
220-1102 Practice Question: During a security audit, you find that a user's…
During a security audit, you find that a user's browser has an outdated version of Adobe Flash Player installed. What is the primary security risk associated with this finding?
⚠ Common exam trap
CompTIA often tests the distinction between operational issues (performance, compatibility) and actual security vulnerabilities, trapping candidates who confuse 'annoying' with 'dangerous'.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Attackers can exploit known vulnerabilities in the plugin to install malware.
Outdated Adobe Flash Player versions contain publicly known vulnerabilities (CVEs) that attackers can exploit via drive-by downloads or malicious advertisements. Exploiting these flaws allows arbitrary code execution, enabling malware installation without user interaction. This is the primary security risk because unpatched plugins are a common entry point for ransomware, spyware, and botnets.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
The browser will run slower and may crash frequently.
Why it's wrong here
Outdated plugins can sometimes introduce performance issues, such as slower browser response times or occasional crashes, due to compatibility conflicts with newer browser versions or operating systems. However, while these are potential consequences, the primary and most significant risk associated with an outdated plugin, especially in the context of a security audit, is not performance degradation but the severe security vulnerabilities it presents to the system.
- ✗
The user will be unable to view some web content.
Why it's wrong here
An outdated plugin might indeed cause compatibility problems, leading to situations where a user cannot properly view or interact with specific web content that requires a more current version of the plugin or relies on different rendering technologies. While this is a legitimate usability concern that affects the user experience, the most critical issue identified during a security audit of an outdated plugin is not content display failure, but rather the unpatched security holes that could be exploited.
- ✓
Attackers can exploit known vulnerabilities in the plugin to install malware.
Why this is correct
Outdated plugins frequently contain publicly documented security vulnerabilities that have been identified and subsequently patched in newer versions. Attackers actively scan for systems running these vulnerable plugin versions and can craft malicious web pages or network requests specifically designed to trigger these known flaws. Successful exploitation can grant the attacker remote code execution privileges, enabling them to install various forms of malware, such as ransomware, keyloggers, or backdoors, directly onto the user's system without their knowledge.
- ✗
The browser will automatically disable the plugin.
Why it's wrong here
While many modern web browsers have implemented features to detect and warn users about outdated or insecure plugins, and some may even block their execution by default, this is not a universal or guaranteed automatic action. The browser's behavior depends on its specific security policies, the plugin type, and the severity of the known vulnerabilities. Even if a browser attempts to disable it, the plugin files still reside on the system, and there might be ways to bypass the browser's block or exploit the plugin through other applications, meaning the underlying security risk persists until it's properly updated or uninstalled.
Go deeper
Related to this question
Learn chapter
Malware Types and Removal
Key term
Ransomware
Ransomware is a type of malicious software that encrypts a victim's files or locks them out of their system, demanding payment, usually in cryptocurrency, to restore access.
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
About these practice questions
Courseiva writes every 220-1202 question from scratch — 495 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This 220-1202 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the 220-1202 exam.