350-201 exam dumps

350-201 practice question 229 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 229

Select 3

A financial organization has discovered a critical vulnerability in one of its web applications after performing a vulnerability scan. The vulnerability has a CVSS (Common Vulnerability Scoring System) score of 9.8, indicating it is easily exploitable and has a severe impact on confidentiality, integrity, and availability. The organization is uncertain about the next steps for vulnerability triage and risk analysis. What should the security team recommend as the next steps?

  1. A

    Assess the exposure of the affected system and prioritize immediate patching or mitigation based on the CVSS score.

  2. B

    Ignore the CVSS score and wait for confirmation of active exploitation in the wild before taking action.

  3. C

    Perform a business impact analysis to evaluate how the vulnerability might affect organizational objectives.

  4. D

    Verify if compensating controls (e.g., firewalls or intrusion prevention systems) are already mitigating the risk.

  5. E

    Recommend decommissioning the affected system immediately without further analysis.

Show answer and explanation

Correct answers: A, C, D

Explanation

For vulnerabilities with a high CVSS score, it is essential to follow a structured triage and risk analysis process. This includes assessing exposure, prioritizing mitigation, understanding the business impact, and evaluating existing controls to determine the best course of action. Ignoring the CVSS score or taking drastic steps like decommissioning without proper analysis can lead to ineffective or overly disruptive responses.

  • A. Correct.

    Assessing the exposure and prioritizing patching or mitigation based on the CVSS score is critical for managing high-risk vulnerabilities effectively. This aligns with industry best practices.

  • B. Incorrect.

    Ignoring the CVSS score and waiting for confirmation of exploitation in the wild is not a recommended practice, as it delays addressing a critical threat and increases the risk of compromise.

  • C. Correct.

    Performing a business impact analysis helps the organization understand the specific risks and consequences of the vulnerability, allowing for better prioritization and decision-making.

  • D. Correct.

    Verifying if compensating controls are in place is an important step to determine if additional mitigation is required or if existing defenses are sufficient.

  • E. Incorrect.

    Decommissioning the system immediately without analysis is an extreme measure and typically not recommended unless the system is already compromised or poses an unacceptable risk that cannot be mitigated.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam