nerdexam
Cisco

350-201 · Question #128

An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response…

The correct answer is A. Implement a patch management process. C. Apply existing patches to the company servers. The Netlogon (Zerologon) vulnerability is a patching issue, so preventing recurrence requires both establishing a patch management process and immediately applying the available patches.

Processes

Question

An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)

Options

  • AImplement a patch management process.
  • BScan the company server files for known viruses.
  • CApply existing patches to the company servers.
  • DAutomate antivirus scans of the company servers.
  • EDefine roles and responsibilities in the incident response playbook.

How the community answered

(24 responses)
  • A
    79% (19)
  • B
    4% (1)
  • D
    13% (3)
  • E
    4% (1)

Why each option

The Netlogon (Zerologon) vulnerability is a patching issue, so preventing recurrence requires both establishing a patch management process and immediately applying the available patches.

AImplement a patch management process.Correct

Implementing a patch management process ensures a systematic, repeatable procedure for identifying, testing, and deploying security patches across the organization, preventing future unpatched vulnerabilities from being exploited.

BScan the company server files for known viruses.

Scanning for known viruses addresses malware infections, not protocol-level vulnerabilities like the Netlogon flaw that enable privilege escalation without malware.

CApply existing patches to the company servers.Correct

Applying existing patches directly remediates the known Netlogon vulnerability (CVE-2020-1472) on company servers, closing the specific privilege escalation vector the attacker used.

DAutomate antivirus scans of the company servers.

Automating antivirus scans would not detect or remediate exploitation of a cryptographic protocol vulnerability such as Zerologon.

EDefine roles and responsibilities in the incident response playbook.

Defining roles in the incident response playbook improves response procedures but does not technically prevent the Netlogon vulnerability from being exploited again.

Concept tested: Patch management to remediate protocol privilege escalation vulnerabilities

Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1472

Topics

#patch management#Netlogon vulnerability#privilege escalation#vulnerability remediation

Community Discussion

No community discussion yet for this question.

Full 350-201 Practice