nerdexam
EC-Council

312-50V13 · Question #318

A post-breach forensic investigation revealed that a known vulnerability in Apache Struts was to blame for the Equifax data breach that affected 143 million customers. A fix was available from the…

The correct answer is D. Patch management. Explanation Patch management is the correct answer because the core failure here was the organization's inability to apply an available security fix (patch) in a timely manner - the vendor had already released a corrective update months before the breach occurred, meaning…

Submitted by yaw92· Mar 6, 2026Vulnerability Analysis

Question

A post-breach forensic investigation revealed that a known vulnerability in Apache Struts was to blame for the Equifax data breach that affected 143 million customers. A fix was available from the software vendor for several months prior 10 the Intrusion. This Is likely a failure in which of the following security processes?

Options

  • Avendor risk management
  • BSecurity awareness training
  • CSecure deployment lifecycle
  • DPatch management

How the community answered

(43 responses)
  • A
    7% (3)
  • B
    2% (1)
  • C
    2% (1)
  • D
    88% (38)

Explanation

Explanation

Patch management is the correct answer because the core failure here was the organization's inability to apply an available security fix (patch) in a timely manner - the vendor had already released a corrective update months before the breach occurred, meaning Equifax simply failed to deploy it. Vendor risk management (A) is incorrect because the issue isn't about evaluating or monitoring the third-party vendor (Apache); the vendor actually did their job by releasing a fix promptly. Security awareness training (B) is wrong because this wasn't a social engineering or human behavior issue - it was a technical failure to update software. Secure deployment lifecycle (C), while related to building security into development processes, focuses more on how software is built rather than how existing software vulnerabilities are maintained and updated.

Memory Tip: Think of patch management as your "security hygiene routine" - just like brushing your teeth daily prevents decay, regularly applying patches prevents attackers from exploiting known vulnerabilities. If a fix exists and you don't apply it, that's always a patch management failure.

Topics

#Patch management#Vulnerability management#Security processes#Software vulnerabilities

Community Discussion

No community discussion yet for this question.

Full 312-50V13 Practice