200-201 exam dumps

200-201 practice question 45 of 405

Cisco Cybersecurity Associate. Associate level, Cisco. Free question with the correct answer and a full explanation.

200-201 Question 45

Select 3

You are working as a cybersecurity analyst and discover that a critical web application on your organization's server is running an outdated version of its content management system (CMS). This version is known to allow remote code execution if exploited. What should your next steps include to address this vulnerability effectively?

  1. A

    Immediately update the CMS to the latest version after testing in a controlled environment.

  2. B

    Monitor the server logs for any suspicious activity but leave the CMS version unchanged.

  3. C

    Apply a virtual patch or Web Application Firewall (WAF) rule to mitigate the vulnerability temporarily.

  4. D

    Document the vulnerability and wait for the next routine maintenance window to address it.

  5. E

    Conduct a risk assessment to determine the potential impact of this vulnerability before taking action.

Show answer and explanation

Correct answers: A, C, E

Explanation

Addressing a critical vulnerability requires a balance of immediate mitigation and long-term resolution. Updating the CMS after testing ensures the vulnerability is fully resolved, while applying virtual patches or WAF rules provides temporary protection. Conducting a risk assessment helps in understanding the potential impact and prioritizing remediation efforts effectively. Leaving the vulnerability unaddressed or delaying action is not acceptable in a cybersecurity context.

  • A. Correct.

    Updating the CMS to the latest version is the most effective way to eliminate the vulnerability, but it should be done carefully after testing to ensure compatibility and functionality.

  • B. Incorrect.

    Simply monitoring server logs without addressing the vulnerability leaves the system exposed to exploitation and is not a proactive solution.

  • C. Correct.

    Applying a virtual patch or WAF rule is a recommended immediate action to mitigate the risk while preparing for a full patch or update.

  • D. Incorrect.

    Delaying action until the next routine maintenance window increases the risk of exploitation, especially for a critical vulnerability with known exploits.

  • E. Correct.

    Conducting a risk assessment helps prioritize the vulnerability and ensures that the appropriate actions are taken based on the severity of the impact.

Timed practice exam

Take a 200-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam