In a public security advisory, which sentence correctly uses agentless passive voice because the attacker's identity is unknown or irrelevant to disclose?
"The vulnerability was exploited on March 3rd" is the correct agentless passive: it foregrounds the affected system and simply omits the "by..." phrase, which is the standard, professional way to state that an event occurred without naming or speculating about the actor. Option A uses vague active voice with "someone", which is less standard in formal disclosures than a clean passive. Option C unnecessarily adds "by an unknown actor", which is redundant since omitting the agent already implies the actor is not being named. Option D misuses passive morphology on an intransitive-sounding reflexive action, which is not idiomatic.
2 / 26
Which sentence correctly uses agentless passive voice to describe a security fix without naming the individual engineer, appropriate for a public changelog?
"The SQL injection flaw was patched in version 4.2.1" correctly uses the agentless passive to keep the focus on the vulnerability and the fix rather than on who performed it, which is standard practice in public-facing security changelogs where individual attribution is unnecessary or undesirable. Option A names the individual engineer, which is inappropriate for a public advisory. Option C misuses a reflexive-sounding construction that implies the flaw fixed itself, which is nonsensical. Option D is an it-cleft that emphasizes the agent, the opposite of the intended agentless effect.
3 / 26
Which sentence correctly uses agentless passive voice to report that customer data was accessed, without confirming who accessed it, in a breach notification?
"Customer records were accessed between June 1st and June 5th" correctly uses the agentless passive, appropriate when the company wants to disclose the fact of the access without prematurely confirming attribution, which may still be under investigation. Option B misuses a reflexive form that is not standard English. Option C names "attackers" as the confirmed agent, which overstates certainty that may not yet be established. Option D adds "by attackers" at the end, reintroducing the agent the sentence is meant to omit, and unnecessarily switches to past continuous.
4 / 26
Which sentence correctly uses agentless passive voice in a vulnerability disclosure to describe a fix being deployed, focusing on the system state rather than the deployment team?
"The patch was deployed to all production servers by 6 a.m." is the correct agentless passive: it centers the patch and its rollout status, appropriately omitting who performed the deployment, which is standard for public advisories that focus on remediation status rather than internal team credit. Option B is active voice that names the internal team, unnecessary detail for external readers. Option C misuses "deployed" as if it were intransitive, but "deploy" normally requires an object or passive marking, making this ungrammatical here. Option D reintroduces the agent ("by the on-call team") after the passive, defeating the purpose of omitting it.
5 / 26
Which sentence correctly keeps the agent in the passive voice because naming the responsible party is specifically required for accountability, contrasting with the agentless pattern used elsewhere in the advisory?
"The misconfiguration was introduced by a third-party contractor during the October migration" is correct: this is passive voice with the agent explicitly retained via "by a third-party contractor" because accountability requires naming who was responsible, unlike the agentless examples used when the actor is unknown or irrelevant. Option B omits the agent entirely, which would be inappropriate here since accountability is the point. Option C is grammatically valid active voice but does not demonstrate the passive-with-agent structure being tested. Option D is missing the auxiliary "was", making it an incomplete sentence rather than a full passive clause.
6 / 26
You're drafting a Slack message to inform the security team about a newly discovered vulnerability. The message reads: 'Sensitive data was accessed via a flawed SQL query.' Which revision most effectively utilizes agentless passive voice for this critical notification?
This question focuses on the urgency and clarity of agentless passive voice in an incident notification. It's crucial to avoid assigning blame or identifying the specific individual involved during a security breach. Option 2 correctly frames the action as occurring *to* the data, prioritizing immediate awareness without further detail. Options A and B reintroduce the agent, while option D is awkward phrasing.
7 / 26
In a pull request description for a security patch, you want to describe how the vulnerability was resolved. The text reads: 'The outdated library version was updated.' Which phrasing best exemplifies agentless passive voice suitable for this scenario?
This question tests the appropriate use of agentless passive voice in a technical PR description. The goal is to provide concise information about the action taken without drawing attention to the specific individuals involved. Option 3 is the most direct and effective, focusing solely on the completed action: the library update. Options A and B add unnecessary details, while option C shifts the focus from the *what* to the *why*.
8 / 26
During a daily standup meeting, David reports: 'The firewall rules were updated to block the malicious traffic.' Which sentence best demonstrates agentless passive voice in this context?
This question targets the use of agentless passive voice in a conversational setting – a standup. The emphasis is on reporting the action taken rather than attributing it to a specific person. Option 3 correctly conveys this without mentioning David directly. Options A and B reintroduce the agent, while option C adds irrelevant details about its importance.
9 / 26
A security incident report states: 'The database server was compromised.' Which revision most accurately utilizes agentless passive voice to describe this event?
This question tests the core use of agentless passive voice in a formal security report. When the identity of the attacker is unknown or unimportant to convey, focusing on the *state* of the system – 'compromised' – is paramount. Options A and B both reintroduce an unnecessary agent, while option C adds detail that isn't essential for this initial reporting.
10 / 26
You're drafting a Slack message to inform the security team about a newly discovered vulnerability. The message reads: 'Sensitive data was accessed via a flawed SQL query.' Which revision most effectively utilizes agentless passive voice for this critical notification?
This question focuses on the urgency and clarity of agentless passive voice in an incident notification. It's crucial to avoid assigning blame or identifying the specific individual involved during a security breach. Option 2 correctly frames the action as occurring *to* the data, prioritizing immediate awareness without further detail. Options A and B reintroduce the agent, while option D is awkward phrasing.
11 / 26
In a pull request description for a security patch, you want to describe how the vulnerability was resolved. The text reads: 'The outdated library version was updated.' Which phrasing best exemplifies agentless passive voice suitable for this scenario?
This question tests the appropriate use of agentless passive voice in a technical PR description. The goal is to provide concise information about the action taken without drawing attention to the specific individuals involved. Option 3 is the most direct and effective, focusing solely on the completed action: the library update. Options A and B add unnecessary details, while option C shifts the focus from the *what* to the *why*.
12 / 26
During a daily standup meeting, David reports: 'The firewall rules were updated to block the malicious traffic.' Which sentence best demonstrates agentless passive voice in this context?
This question targets the use of agentless passive voice in a conversational setting – a standup. The emphasis is on reporting the action taken rather than attributing it to a specific person. Option 3 correctly conveys this without mentioning David directly. Options A and B reintroduce the agent, while option C adds irrelevant details about its importance.
13 / 26
A security incident report states: 'The database server was compromised.' Which revision most accurately utilizes agentless passive voice to describe this event?
This question tests the core use of agentless passive voice in a formal security report. When the identity of the attacker is unknown or unimportant to convey, focusing on the *state* of the system – 'compromised' – is paramount. Options A and B both reintroduce an unnecessary agent, while option C adds detail that isn't essential for this initial reporting.
14 / 26
You're drafting a Slack message to inform the security team about a newly discovered vulnerability. The message reads: 'Sensitive data was accessed via a flawed SQL query.' Which revision most effectively utilizes agentless passive voice for this critical notification?
This question focuses on the urgency and clarity of agentless passive voice in an incident notification. It's crucial to avoid assigning blame or identifying the specific individual involved during a security breach. Option 2 correctly frames the action as occurring *to* the data, prioritizing immediate awareness without further detail. Options A and B reintroduce the agent, while option D is awkward phrasing.
15 / 26
In a pull request description for a security patch, you want to describe how the vulnerability was resolved. The text reads: 'The outdated library version was updated.' Which phrasing best exemplifies agentless passive voice suitable for this scenario?
This question tests the appropriate use of agentless passive voice in a technical PR description. The goal is to provide concise information about the action taken without drawing attention to the specific individuals involved. Option 3 is the most direct and effective, focusing solely on the completed action: the library update. Options A and B add unnecessary details, while option C shifts the focus from the *what* to the *why*.
16 / 26
During a daily standup meeting, David reports: 'The firewall rules were updated to block the malicious traffic.' Which sentence best demonstrates agentless passive voice in this context?
This question targets the use of agentless passive voice in a conversational setting – a standup. The emphasis is on reporting the action taken rather than attributing it to a specific person. Option 3 correctly conveys this without mentioning David directly. Options A and B reintroduce the agent, while option C adds irrelevant details about its importance.
17 / 26
A security incident report states: 'The database server was compromised.' Which revision most accurately utilizes agentless passive voice to describe this event?
This question tests the core use of agentless passive voice in a formal security report. When the identity of the attacker is unknown or unimportant to convey, focusing on the *state* of the system – 'compromised' – is paramount. Options A and B both reintroduce an unnecessary agent, while option C adds detail that isn't essential for this initial reporting.
18 / 26
Sarah is reviewing a pull request describing a recent vulnerability. The developer wrote: 'A critical SQL injection flaw was exploited in the user authentication service.' Which revision best demonstrates agentless passive voice and focuses on the security impact without assigning blame?
Agentless passive voice omits the actor performing the action. Option 1 retains the original phrasing which is correct and focuses on the *impact* of the vulnerability - a critical flaw exploited. Options 2 & 3 incorrectly introduce 'attack' or 'experience', adding unnecessary detail and potentially implying blame. Option 4 explicitly names the attacker, violating the principle of agent omission.
19 / 26
During a Slack conversation about a data breach, Alex writes: 'Sensitive customer records were accessed without authorization.' Which revision most effectively utilizes agentless passive voice to convey the seriousness of the incident while avoiding direct accusations?
This option correctly uses agentless passive voice – 'were accessed' – to describe the action. It focuses on *what* happened (access) and *who* was affected (sensitive customer records), avoiding assigning blame or identifying a specific perpetrator. Options 2 incorrectly adds 'sensitive', while options 3 and 4 introduce an actor ('someone') which contradicts agent omission.
20 / 26
You're drafting a security advisory for a newly discovered vulnerability in a web application. The advisory states: 'Unvalidated user input was used to construct SQL queries.' Which revision best exemplifies agentless passive voice and highlights the root cause of the problem?
Option 1 is the most concise and accurate use of agentless passive voice. 'Was used' describes the action performed by the input without specifying *who* or *what* was using it. Options 2 incorrectly reverses the sentence structure, adding unnecessary detail. Options 3 and 4 rephrase the statement in a more active style, departing from the core principle of agent omission.
21 / 26
During a code review, you're examining a commit message related to a recent firewall update. The original message reads: 'The firewall was updated to mitigate the DDoS attack.' Which revision best demonstrates agentless passive voice in this context, emphasizing the action taken without specifying who performed it?
The key to agentless passive voice is focusing on the action itself. Option 2 correctly highlights 'the firewall rules were updated,' omitting the actor (the security team or automated system). Options A and B introduce irrelevant information about logs/traffic, while option D suggests a further action instead of describing what happened.
22 / 26
You're writing a PR description for a security patch. The original text states: 'The vulnerability was identified through automated scanning.' Which revision best exemplifies agentless passive voice and accurately reflects the process without assigning responsibility?
Agentless passive voice prioritizes the action of scanning. Option 1 correctly states 'the vulnerability was found using automated tools,' avoiding any mention of who performed the scan. Options A and B introduce unnecessary detail about human intervention or effectiveness, while option C suggests an alternative approach.
23 / 26
Alex, a security engineer, is drafting an email to the development team regarding a recent vulnerability. He writes: 'A potential cross-site scripting (XSS) vulnerability was identified during automated testing.' Which revision best utilizes agentless passive voice to improve clarity and professionalism in this communication?
This option correctly employs agentless passive voice—'A potential XSS vulnerability was identified.'—focusing on the *result* of the automated testing rather than who performed it. Option A incorrectly introduces an agent ('by automated testing'), while options B and D are overly verbose and less precise. The key is to emphasize the action's outcome, not the actor.
24 / 26
Liam has submitted a pull request with the following description: 'The API endpoint was modified to prevent unauthorized access.' As a code reviewer, which of the following revisions most effectively demonstrates agentless passive voice and clarifies the security improvement?
Option 3 is the most concise and effective use of agentless passive voice. It clearly states what happened ('the API endpoint was modified') without explicitly naming the actor (Liam). Options A and B unnecessarily add 'by Liam', which is often omitted in security-related descriptions. Option D repeats the purpose, rather than describing the action itself.
25 / 26
As a security engineer, you're drafting an email to the DevOps team detailing a recent incident. The draft reads: 'A critical vulnerability was discovered in the application's logging system.' Which revision best utilizes agentless passive voice to clearly communicate the severity of the issue and avoid assigning blame?
This option correctly employs agentless passive voice, focusing on the action (vulnerability discovered) without identifying who or what performed it. The other options introduce agency ('our team') which is generally undesirable in formal security communications, and rephrase the core issue unnecessarily. Agentless phrasing is preferred for clarity and neutrality when reporting vulnerabilities.
26 / 26
You're writing a PR description to explain a recent firewall update. The original commit message states: 'The firewall rules were updated to block the malicious traffic.' Which revision most effectively conveys this information concisely and professionally?
Option 2 is the most accurate and concise use of agentless passive voice. It directly states what happened without assigning blame or providing unnecessary detail. Options 1 and 3 introduce agency, while option 4 uses a more complex phrasing that isn't required here.
What will I practise in "Passive Voice with Agent Omission in Security Disclosures — IT Grammar Exercise"?
Practise choosing when to omit the "by..." agent phrase in passive voice for security advisories and breach notifications, and when accountability requires
How many exercises are in this module?
This module has 26 multiple-choice exercises, each with instant feedback and a full explanation of the correct answer.
Is this exercise free to use?
Yes. Every exercise on CoderSlingo, including this one, is free to use with no account, sign-up, or paywall.
Do I need to create an account to do these exercises?
No account is required. Just click an option to answer — your score for this session is tracked automatically in the progress bar above.
What happens if I choose the wrong answer?
You'll immediately see which answer was correct, plus a full explanation covering the grammar rule and reasoning behind it — mistakes are where most of the learning happens.
Can I retry the exercises if I want a higher score?
Yes — use the "Try again" button on the results screen to reset and go through all the questions again.
Is my progress saved if I close the page?
No. Progress is tracked only for your current visit; reloading or leaving the page resets the counter. This keeps the exercise simple and account-free.
Where can I find more Grammar exercises?
Browse the full Grammar hub for related drills, or check the "Next up" link below to continue with a connected topic.
How is this different from reading an article on the same topic?
Articles explain grammar rules in prose; this exercise tests and reinforces those rules through active recall with immediate feedback — the two work best together.
Who writes these exercises?
Every exercise is written by the CoderSlingo team, drawing on real workplace English used in IT roles, then reviewed for accuracy and clarity.