100-160 exam dumps

100-160 practice question 191 of 265

Cisco Certified Support Technician (CCST) Cybersecurity. Associate level, Cisco. Free question with the correct answer and a full explanation.

100-160 Question 191

Select 3

A cybersecurity analyst discovers a new vulnerability in a company’s web application. To address the issue effectively, which actions should the analyst prioritize to ensure the vulnerability is managed properly while maintaining accurate documentation and communication?

  1. A

    Check the vulnerability against a trusted vulnerability database, such as the NVD, to identify its CVE ID and severity.

  2. B

    Rely solely on cybersecurity news websites to gather information about the vulnerability.

  3. C

    Document the vulnerability details, mitigation steps, and resolution in the organization’s incident response system.

  4. D

    Set up automated alerts for any updates regarding the vulnerability from threat intelligence platforms.

  5. E

    Share vulnerability details publicly on social media to gather external feedback before mitigation.

Show answer and explanation

Correct answers: A, C, D

Explanation

Effectively managing a vulnerability requires leveraging trusted resources like vulnerability databases and threat intelligence platforms to assess the issue and monitor updates. Additionally, documenting the process is crucial for accountability and future reference. Publicly sharing sensitive information is a poor practice that could lead to further security risks.

  • A. Correct.

    Trusted vulnerability databases, like the National Vulnerability Database (NVD), provide detailed information about vulnerabilities, including CVE IDs, severity ratings, and mitigation recommendations. This is a key step for proper vulnerability management.

  • B. Incorrect.

    While cybersecurity news websites can provide general updates, they are not a reliable or comprehensive source for managing vulnerabilities. Analysts should rely on industry-standard tools and databases.

  • C. Correct.

    Documenting the vulnerability, mitigation steps, and resolution ensures that the organization has a clear record for auditing, learning, and compliance purposes. This is a critical best practice in cybersecurity.

  • D. Correct.

    Setting up automated alerts from threat intelligence platforms ensures the analyst can stay up-to-date on any changes or updates to the vulnerability, assisting in timely responses.

  • E. Incorrect.

    Sharing vulnerability details publicly on social media is not a secure or professional practice. This could expose sensitive information and make the organization more vulnerable to attacks.

Timed practice exam

Take a 100-160 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam