312-50V13 · Question #318
A post-breach forensic investigation revealed that a known vulnerability in Apache Struts was to blame for the Equifax data breach that affected 143 million customers. A fix was available from the…
The correct answer is D. Patch management. Explanation Patch management is the correct answer because the core failure here was the organization's inability to apply an available security fix (patch) in a timely manner - the vendor had already released a corrective update months before the breach occurred, meaning…
Question
Options
- Avendor risk management
- BSecurity awareness training
- CSecure deployment lifecycle
- DPatch management
How the community answered
(43 responses)- A7% (3)
- B2% (1)
- C2% (1)
- D88% (38)
Explanation
Explanation
Patch management is the correct answer because the core failure here was the organization's inability to apply an available security fix (patch) in a timely manner - the vendor had already released a corrective update months before the breach occurred, meaning Equifax simply failed to deploy it. Vendor risk management (A) is incorrect because the issue isn't about evaluating or monitoring the third-party vendor (Apache); the vendor actually did their job by releasing a fix promptly. Security awareness training (B) is wrong because this wasn't a social engineering or human behavior issue - it was a technical failure to update software. Secure deployment lifecycle (C), while related to building security into development processes, focuses more on how software is built rather than how existing software vulnerabilities are maintained and updated.
Memory Tip: Think of patch management as your "security hygiene routine" - just like brushing your teeth daily prevents decay, regularly applying patches prevents attackers from exploiting known vulnerabilities. If a fix exists and you don't apply it, that's always a patch management failure.
Topics
Community Discussion
No community discussion yet for this question.