Zero-day
In one sentence
A brand-new software flaw attackers exploit before the vendor has released a fix.
A zero-day is a vulnerability unknown to the vendor (so there's 'zero days' of warning) being actively exploited. Defenses lean on layered controls (EDR, least privilege, monitoring) since patching isn't yet possible.
How the Readiness Check scores it
The free Check asks the same question a carrier will. Here it is, why it's asked, and the fix if today's honest answer is no. The full application question list has the rest.
Patching & vulnerabilities
How are security updates applied to your systems and software?
Why carriers ask: Unpatched, internet-facing software is now a leading initial-access vector. Applications ask about patch cadence and end-of-life systems specifically.
If the answer is no: Have whoever manages IT produce a list of what's patched automatically vs. manually. That list becomes your patch-management policy's appendix.
The written evidence carriers accept
A “yes” on the application needs a document behind it. In the Readiness Pack, that document is:
Related terms
Would you pass this question today?
The free Readiness Check scores you across the ten control domains carriers probe, in five minutes, no email required for the score.