350-201 exam dumps

350-201 practice question 232 of 289

Cybersecurity Professional - Performing Cybersecurity Using Cisco Security Technologies. Professional level, Cisco. Free question with the correct answer and a full explanation.

350-201 Question 232

Select 3

An organization has identified a critical vulnerability in a web application used to process sensitive customer data. The vulnerability has been assigned a CVSS score of 9.8. What should be the next steps for the security team to prioritize and address this vulnerability?

  1. A

    Verify the accuracy of the CVSS score by analyzing the exploitability and impact metrics.

  2. B

    Immediately deploy a patch to mitigate the vulnerability without further assessment.

  3. C

    Assess the business impact of the vulnerability if exploited in the organization's specific environment.

  4. D

    Monitor for active exploitation attempts while scheduling remediation during the next maintenance window.

  5. E

    Consult with the vendor or third-party security advisories for additional mitigation strategies.

Show answer and explanation

Correct answers: A, C, E

Explanation

When addressing a critical vulnerability with a high CVSS score, the security team must verify the accuracy of the score, assess the business impact specific to their environment, and consult trusted sources for mitigation strategies. These steps ensure a comprehensive understanding of the risk and help develop a balanced remediation plan. While monitoring for exploitation attempts and scheduling remediation are important, they do not replace the need for immediate analysis and planning for high-severity vulnerabilities.

  • A. Correct.

    Verifying the CVSS score is critical to ensure the assigned severity aligns with the actual risk to the organization. This step ensures the security metrics used for prioritization are accurate.

  • B. Incorrect.

    Deploying a patch immediately without further assessment may lead to unintended consequences, such as system downtime or compatibility issues. Proper evaluation is necessary before implementing changes.

  • C. Correct.

    Assessing the business impact is essential because the CVSS score represents a general severity level and does not account for the organization's unique environment or risk tolerance.

  • D. Incorrect.

    Monitoring for exploitation attempts is a good practice, but delaying remediation until the next maintenance window for a critical vulnerability with a CVSS score of 9.8 is not advisable as it increases exposure to potential attacks.

  • E. Correct.

    Consulting vendor or third-party advisories provides additional insight into mitigation strategies and potential workarounds if immediate patching is not feasible.

Timed practice exam

Take a 350-201 practice test under exam conditions

75 questions in 120 minutes, drawn from this bank, with a score report and a per-question review when you finish.

Start timed exam