300-215 Question 133
Select 3After a recent ransomware attack, your organization has completed the incident containment and eradication phases. During the post-incident analysis, it was discovered that an outdated vulnerability management process contributed to the attack. Which of the following actions should you recommend to strengthen the organization's security posture and prevent similar incidents in the future?
- A
Implement a patch management solution to automatically apply critical updates.
- B
Conduct regular penetration testing to identify exploitable vulnerabilities.
- C
Establish a threat intelligence sharing program with industry peers.
- D
Increase endpoint logging retention from 30 days to 6 months.
- E
Focus solely on user awareness training to prevent phishing attacks.
Show answer and explanation
Correct answers: A, B, C
Explanation
The correct actions focus on addressing the root cause of the incident (outdated vulnerability management) while enhancing the organization's ability to prevent, detect, and respond to security threats. Patch management, penetration testing, and threat intelligence sharing are proactive measures that directly reduce the likelihood of similar incidents. Logging retention and user awareness training, while beneficial, are not sufficient on their own to address the specific issue at hand.
- A. Correct.
This option is correct because implementing a patch management solution ensures that vulnerabilities are addressed promptly, reducing the risk of exploitation.
- B. Correct.
This option is correct because regular penetration testing helps identify and mitigate potential vulnerabilities before they can be exploited by attackers.
- C. Correct.
This option is correct because sharing threat intelligence with peers can help the organization stay informed about emerging threats and adjust defenses accordingly.
- D. Incorrect.
While increasing logging retention can improve forensic analysis, it does not directly address the root cause of the incident, which was related to vulnerability management.
- E. Incorrect.
While user awareness training is important, focusing solely on this area does not comprehensively address the outdated vulnerability management process that led to the attack.