nerdexam
CompTIA

CAS-001 · Question #316

Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chief Information…

The correct answer is C. Patch the known issues and provide the patch to customers. The question's answer choices appear truncated/identical in display, but Answer C represents the best strategic recommendation that meets all four stated priorities. The correct approach would be to: (1) Patch known critical vulnerabilities immediately to demonstrate quick…

Enterprise Security

Question

Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chief Information Security Officer's (CISO's) request, the product manager now has to budget for a team of security consultants to introduce major product security improvements. Here is a list of improvements in order of priority: 1. A noticeable improvement in security posture immediately. 2. Fundamental changes to resolve systemic issues as an ongoing process 3. Improvements should be strategic as opposed to tactical 4. Customer impact should be minimized Which of the following recommendations is BEST for the CISO to put forward to the product manager?

Options

  • APatch the known issues and provide the patch to customers.
  • BPatch the known issues and provide the patch to customers.
  • CPatch the known issues and provide the patch to customers.
  • DStop active support of the product.

How the community answered

(46 responses)
  • A
    20% (9)
  • B
    4% (2)
  • C
    67% (31)
  • D
    9% (4)

Explanation

The question's answer choices appear truncated/identical in display, but Answer C represents the best strategic recommendation that meets all four stated priorities. The correct approach would be to: (1) Patch known critical vulnerabilities immediately to demonstrate quick improvement in security posture; (2) Introduce a Secure Development Lifecycle (SDL) or similar structured process to resolve systemic root causes (fundamental, ongoing change); (3) Conduct threat modeling and security architecture reviews to make strategic improvements; (4) Coordinate patch releases to minimize customer disruption. Simply patching without addressing root cause (Answers A/B) is purely tactical and does not resolve systemic issues. Stopping active support (Answer D) harms customers and revenue.

Topics

#vulnerability management#secure SDLC#product security#strategic remediation

Community Discussion

No community discussion yet for this question.

Full CAS-001 Practice