350-201 exam dumps

350-201 practice question 226 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 226

Select 3

Your organization recently conducted a vulnerability assessment, which revealed that a critical web server is running an outdated version of its software, exposing it to known exploits. As the cybersecurity engineer, what general steps should you recommend to mitigate this vulnerability?

  1. A

    Apply the latest security patches to the web server software.

  2. B

    Disable the server to prevent any exploitation until the vulnerability is resolved.

  3. C

    Implement network segmentation to restrict access to the vulnerable server.

  4. D

    Update access controls to limit user permissions on the server.

  5. E

    Monitor server logs for unusual activity and potential exploitation attempts.

Show answer and explanation

Correct answers: A, C, E

Explanation

Mitigating vulnerabilities requires a combination of addressing the root cause (e.g., applying patches) and implementing interim protective measures (e.g., network segmentation and monitoring). By patching the software, restricting access, and monitoring for potential threats, the organization can effectively reduce the risk of exploitation while maintaining operations.

  • A. Correct.

    Applying the latest security patches is one of the most effective ways to address vulnerabilities, as it removes the known exploit by fixing the underlying software issue.

  • B. Incorrect.

    Disabling the server is not a practical long-term solution and could disrupt business operations unnecessarily. Instead, focus on mitigation and remediation steps.

  • C. Correct.

    Network segmentation can limit the exposure of the vulnerable server to potential attackers, reducing the attack surface and buying time until the vulnerability is resolved.

  • D. Incorrect.

    While updating access controls is a good security practice, it does not specifically address the identified vulnerability in the server software.

  • E. Correct.

    Monitoring server logs can help detect any exploitation attempts or suspicious activity while remediation steps are being implemented, providing critical visibility.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam