350-201 · Question #128
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response…
The correct answer is A. Implement a patch management process. C. Apply existing patches to the company servers. The Netlogon (Zerologon) vulnerability is a patching issue, so preventing recurrence requires both establishing a patch management process and immediately applying the available patches.
Question
An organization suffered a security breach in which the attacker exploited a Netlogon Remote Protocol vulnerability for further privilege escalation. Which two actions should the incident response team take to prevent this type of attack from reoccurring? (Choose two.)
Options
- AImplement a patch management process.
- BScan the company server files for known viruses.
- CApply existing patches to the company servers.
- DAutomate antivirus scans of the company servers.
- EDefine roles and responsibilities in the incident response playbook.
How the community answered
(24 responses)- A79% (19)
- B4% (1)
- D13% (3)
- E4% (1)
Why each option
The Netlogon (Zerologon) vulnerability is a patching issue, so preventing recurrence requires both establishing a patch management process and immediately applying the available patches.
Implementing a patch management process ensures a systematic, repeatable procedure for identifying, testing, and deploying security patches across the organization, preventing future unpatched vulnerabilities from being exploited.
Scanning for known viruses addresses malware infections, not protocol-level vulnerabilities like the Netlogon flaw that enable privilege escalation without malware.
Applying existing patches directly remediates the known Netlogon vulnerability (CVE-2020-1472) on company servers, closing the specific privilege escalation vector the attacker used.
Automating antivirus scans would not detect or remediate exploitation of a cryptographic protocol vulnerability such as Zerologon.
Defining roles in the incident response playbook improves response procedures but does not technically prevent the Netlogon vulnerability from being exploited again.
Concept tested: Patch management to remediate protocol privilege escalation vulnerabilities
Source: https://msrc.microsoft.com/update-guide/vulnerability/CVE-2020-1472
Topics
Community Discussion
No community discussion yet for this question.