Clerk workstations still run an unpatched browser plugin that agentless network scans never inventory, and several drive-by attempts target that plugin. Which attack-surface issue is most directly highlighted?
Select an answer to reveal the explanation.
Short Explanation
That dusty browser plugin on clerk PCs is vulnerable client software — a local foothold scanners may miss if they never look on the endpoint. Patch or remove it; do not confuse it with door-controller firmware or BEC. Client apps are part of the municipal attack surface too.
Full Explanation
Vulnerable client-based software increases endpoint attack surface and may evade agentless network scanning that lacks host inventory. Objective 2.2 ties vulnerable software on clients to expanded exposure requiring patching or control. VM escape, outdated badge firmware, and payment BEC are different classes. Municipal IT should inventory browser plugins and enforce patch or removal policies on clerk workstations.