CAS-001 · Question #316
Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chief Information…
The correct answer is C. Patch the known issues and provide the patch to customers. The question's answer choices appear truncated/identical in display, but Answer C represents the best strategic recommendation that meets all four stated priorities. The correct approach would be to: (1) Patch known critical vulnerabilities immediately to demonstrate quick…
Question
Options
- APatch the known issues and provide the patch to customers.
- BPatch the known issues and provide the patch to customers.
- CPatch the known issues and provide the patch to customers.
- DStop active support of the product.
How the community answered
(46 responses)- A20% (9)
- B4% (2)
- C67% (31)
- D9% (4)
Explanation
The question's answer choices appear truncated/identical in display, but Answer C represents the best strategic recommendation that meets all four stated priorities. The correct approach would be to: (1) Patch known critical vulnerabilities immediately to demonstrate quick improvement in security posture; (2) Introduce a Secure Development Lifecycle (SDL) or similar structured process to resolve systemic root causes (fundamental, ongoing change); (3) Conduct threat modeling and security architecture reviews to make strategic improvements; (4) Coordinate patch releases to minimize customer disruption. Simply patching without addressing root cause (Answers A/B) is purely tactical and does not resolve systemic issues. Stopping active support (Answer D) harms customers and revenue.
Topics
Community Discussion
No community discussion yet for this question.