100-160 exam dumps

100-160 practice question 179 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 179

Single answer

A company has recently implemented a vulnerability management program. During a routine scan, the team identifies several critical vulnerabilities on a web server hosting customer data. What is the most appropriate next step to take according to best practices in vulnerability management?

  1. A

    Immediately shut down the web server to prevent potential exploits.

  2. B

    Prioritize and remediate the vulnerabilities based on their risk to the business.

  3. C

    Ignore the vulnerabilities since no exploit attempts have been detected.

  4. D

    Report the vulnerabilities to the software vendor and wait for a patch before acting.

Show answer and explanation

Correct answer: B

Explanation

Vulnerability management involves identifying, assessing, prioritizing, and remediating vulnerabilities to reduce security risks. In this scenario, the most appropriate step is to prioritize and address the critical vulnerabilities affecting the web server, as they pose a significant risk to business operations and customer data. This approach ensures that the organization maintains a proactive stance in mitigating threats while balancing operational needs.

  • A. Incorrect.

    Immediately shutting down the web server is not always practical or necessary. Vulnerability management focuses on prioritization and remediation rather than immediate system shutdowns unless an exploit is actively being used.

  • B. Correct.

    Prioritizing and remediating vulnerabilities based on their risk to the business aligns with best practices in vulnerability management. Critical vulnerabilities should be addressed as a priority to minimize potential harm.

  • C. Incorrect.

    Ignoring the vulnerabilities is not an acceptable practice in vulnerability management, as it leaves the system exposed to potential attacks.

  • D. Incorrect.

    While reporting vulnerabilities to the vendor is important, waiting for a patch without taking other actions (e.g., applying workarounds or mitigating risks) is not sufficient in a vulnerability management process.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam