200-201 Question 327
Single answerA company has recently deployed a new web application. During a routine vulnerability scan, the security operations team identifies several high-risk vulnerabilities. What should the team prioritize as the next step in the vulnerability management process?
- A
Immediately patch all identified vulnerabilities without further analysis.
- B
Validate the vulnerabilities and assess their potential impact on the organization.
- C
Disable the vulnerability scanner to prevent further interruptions to operations.
- D
Notify end-users and ask them to avoid using the application until further notice.
Show answer and explanation
Correct answer: B
Explanation
In the vulnerability management process, after identifying vulnerabilities, the next step is to validate the findings and assess their potential impact. This ensures that the vulnerabilities are real and enables the organization to prioritize remediation efforts based on the level of risk they pose. Skipping this step could result in ineffective or inefficient resource allocation.
- A. Incorrect.
While patching vulnerabilities is important, it is not advisable to immediately patch all vulnerabilities without validating the findings. False positives could lead to wasted effort or unnecessary disruptions.
- B. Correct.
Validating vulnerabilities and assessing their impact is a critical step in the vulnerability management process. This ensures that the identified issues are real and helps prioritize remediation efforts based on risk.
- C. Incorrect.
Disabling the vulnerability scanner does not address the underlying issue and leaves the organization exposed to potential threats.
- D. Incorrect.
Notifying end-users and asking them to avoid using the application is not a practical or sustainable solution. It does not address the vulnerabilities and could impact business operations.