712-50 Question 355
Single answerA global financial services company has modernized several customer-facing applications using containers and multiple open-source components. The CISO learns from a trusted threat intelligence feed that a newly disclosed vulnerability in a widely used open-source library is being actively exploited in the wild. The organization does not have a consistently maintained software bill of materials (SBOM), and several critical applications are operated by third-party managed service providers. Senior leadership wants a threat management response that reduces immediate risk and improves long-term resilience. Which action should the CISO prioritize FIRST to make the threat management program effective in this situation?
- A
Require all internal development teams and third-party providers to immediately identify whether the vulnerable library is present in production systems, correlate that exposure with exploit intelligence and business criticality, and initiate risk-based containment and patching under a centrally coordinated process
- B
Wait for each application owner to review the next monthly vendor security bulletin cycle before taking action, because emergency changes to open-source components can disrupt service availability
- C
Block all outbound connections from affected applications until a permanent fix is available, since active exploitation intelligence means every potentially exposed system should be isolated regardless of business impact
- D
Focus first on collecting more external threat intelligence feeds to improve confidence in attribution before asking internal teams and third parties to assess exposure
Show answer and explanation
Correct answer: A
Explanation
This scenario tests executive-level threat management, not just technical vulnerability response. A CCISO should ensure threat intelligence is actionable by linking external intelligence about active exploitation to internal exposure, third-party risk, and software/component inventories. Since open-source software is often embedded deep in applications and containers, organizations need mechanisms such as SBOMs, dependency tracking, asset inventories, and contractual requirements for third-party reporting. When those are incomplete, the first priority is a centrally coordinated enterprise-wide exposure assessment that includes managed service providers and key vendors, followed by risk-based containment and remediation.
Relevant best practices include NIST guidance on vulnerability management and supply chain risk management, which emphasize identifying affected assets, prioritizing based on likelihood and impact, and coordinating with suppliers. CISA and many national CERTs also routinely recommend urgent asset identification, exposure scoping, and mitigation when vulnerabilities are known to be actively exploited. Security bulletins and open-source advisories are important inputs, but the program becomes effective only when those signals are integrated into operational workflows, third-party obligations, and executive decision-making.
- A. Correct.
Correct. The most effective first step is to determine organizational exposure quickly, including internal and third-party environments, then prioritize remediation based on exploitability and business criticality. In a mature threat management program, threat intelligence is operationalized by correlating intelligence about active exploitation with asset inventory, dependency information, and business impact. Because the company lacks a mature SBOM capability, the CISO should immediately establish a coordinated exposure assessment across internal teams and managed providers, followed by compensating controls, patching, and escalation for critical systems. This aligns with best practices from NIST vulnerability management and supply chain guidance: identify affected assets, assess risk, and coordinate remediation across the enterprise and suppliers.
- B. Incorrect.
Incorrect. Waiting for a normal monthly bulletin cycle is too slow when credible intelligence indicates active exploitation. Security bulletins are important inputs, but threat management requires timely action when the threat landscape changes. This option reflects a common governance error: treating vulnerability response as a routine compliance process rather than a risk-driven operational capability. Availability concerns matter, but they do not justify delaying exposure identification and risk-based containment.
- C. Incorrect.
Incorrect. Immediate blanket isolation of all possibly affected applications is not an appropriate first action at the executive level because it ignores business criticality, actual exposure, and proportional response. Some systems may not be affected, may not be internet-reachable, or may have effective compensating controls. A CCISO should drive a risk-based process, not a universally disruptive control without confirming scope. Isolation may be warranted for specific high-risk assets after exposure assessment, but not as the first enterprise-wide action.
- D. Incorrect.
Incorrect. Additional threat feeds may provide context, but attribution is not the key decision factor for initial response. The urgent need is to identify whether the vulnerable component exists in the environment and whether exploit conditions are present. This option reflects a misconception that more intelligence collection is always the best next step. In reality, threat intelligence only adds value when translated into internal action such as scoping, prioritization, containment, and remediation.