100-160 Question 175
Select 2A small retail company recently conducted a vulnerability assessment on their network and identified a critical vulnerability in their payment processing system. As the cybersecurity technician, you are tasked with determining the next steps to mitigate the risk. Which actions should you prioritize?
- A
Patch the vulnerability immediately to prevent potential exploitation.
- B
Conduct further research to determine if the vulnerability has been exploited.
- C
Contact the payment processing vendor for a recommended fix or solution.
- D
Temporarily disable the payment processing system until the vulnerability is resolved.
- E
Document the vulnerability and delay remediation until the next scheduled maintenance window.
Show answer and explanation
Correct answers: A, C
Explanation
When dealing with a critical vulnerability in a system, the primary focus should be on mitigating the risk as quickly as possible. Patching the vulnerability and consulting the vendor for guidance are both high-priority actions to ensure the system is secured without unnecessary downtime or risk. Other actions, such as research or documentation, should not take precedence over mitigation.
- A. Correct.
Patching the vulnerability immediately is crucial to prevent exploitation, especially since it has been identified as critical. Delaying this action increases the risk of a security breach.
- B. Incorrect.
While conducting further research is important, it should not delay the immediate mitigation of a critical vulnerability. Research can be performed in parallel or after the fix is applied.
- C. Correct.
Contacting the vendor is a key step to ensure the correct and safest solution is applied, as they can provide guidance or updates specific to the system.
- D. Incorrect.
Temporarily disabling the payment processing system may be unnecessarily disruptive to business operations. This should only be considered if no patch or vendor guidance is available and the risk is imminent.
- E. Incorrect.
Delaying remediation of a critical vulnerability until the next maintenance window is not recommended, as it unnecessarily exposes the system to potential exploitation.