CAS-001 · Question #168
New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the risks of these…
The correct answer is B. Create an inventory of applications. D. Maintain a list of critical systems. Managing zero-day risk requires knowing what assets and critical systems you have so you can quickly assess exposure when a new vulnerability is announced.
Question
New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the risks of these attack vectors? (Select TWO).
Options
- AEstablish an emergency response call tree.
- BCreate an inventory of applications.
- CBackup the router and firewall configurations.
- DMaintain a list of critical systems.
- EUpdate all network diagrams.
How the community answered
(38 responses)- A5% (2)
- B84% (32)
- C8% (3)
- E3% (1)
Why each option
Managing zero-day risk requires knowing what assets and critical systems you have so you can quickly assess exposure when a new vulnerability is announced.
An emergency response call tree addresses incident communication logistics but does not help the team assess or reduce exposure to zero-day attack vectors.
Maintaining an inventory of applications allows security teams to immediately determine whether a newly announced zero-day affects any software in the environment, enabling rapid and targeted risk assessment.
Backing up router and firewall configurations supports disaster recovery but does not directly help identify which systems are vulnerable to a newly disclosed zero-day.
A list of critical systems allows the security manager to prioritize response and mitigation efforts by identifying which zero-day-affected systems pose the greatest business risk if compromised.
Updating network diagrams improves documentation but does not directly enable rapid identification of which applications or critical systems are exposed to a zero-day vulnerability.
Concept tested: Zero-day risk management through asset and system inventory
Source: https://www.cisa.gov/sites/default/files/publications/CISA_Insights_Mitigations_and_Hardening_Guidance_for_MSPs_and_Small-and-Mid-sized_Businesses.pdf
Topics
Community Discussion
No community discussion yet for this question.