212-89 · Question #70
During the vulnerability assessment phase, the incident responders perform various steps as below: 1. Run vulnerability scans using tools 2. Identify and prioritize vulnerabilities 3. Examine and…
The correct answer is C. 4-->1-->2-->3-->6-->5-->7. The correct sequence of steps performed by incident responders during the vulnerability assessment phase is as follows: Perform OSINT information gathering to validate the vulnerabilities (4): Initially, Open Source Intelligence (OSINT) is used to gather information about the…
Question
Options
- A3-->6-->1-->2-->5-->4-->7
- B1-->3-->2-->4-->5-->6-->7
- C4-->1-->2-->3-->6-->5-->7
- D2-->1-->4-->7-->5-->6-->3
How the community answered
(45 responses)- A4% (2)
- B7% (3)
- C73% (33)
- D16% (7)
Explanation
The correct sequence of steps performed by incident responders during the vulnerability assessment phase is as follows: Perform OSINT information gathering to validate the vulnerabilities (4): Initially, Open Source Intelligence (OSINT) is used to gather information about the organization's digital footprint and potential vulnerabilities. Run vulnerability scans using tools (1): Next, specialized tools are employed to scan the organization's networks and systems for vulnerabilities. Identify and prioritize vulnerabilities (2): The identified vulnerabilities are then analyzed and prioritized based on their severity and potential impact on the organization. Examine and evaluate physical security (3): Physical security assessments are also crucial as they can impact the overall security posture and protection of digital assets. Check for misconfigurations and human errors (6): This step involves looking for misconfigurations in systems and networks, as well as potential human errors that could lead to vulnerabilities. Apply business and technology context to scanner (5): The results from the scans are evaluated within the context of the business and its technology environment to accurately assess risks. Create a vulnerability scan report (7): Finally, a comprehensive report is created, detailing the vulnerabilities, their severity, and recommended mitigation strategies. This sequence ensures a thorough assessment, prioritizing vulnerabilities that pose the greatest risk and providing actionable insights for mitigation.
Topics
Community Discussion
No community discussion yet for this question.