nerdexam
CompTIA

CAS-002 · Question #148

New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the risks of these…

The correct answer is B. Create an inventory of applications. D. Maintain a list of critical systems. Managing zero-day risk requires knowing what you have - an application inventory identifies exposed software, and a critical systems list enables prioritized triage and response. Without knowing what is deployed and what is critical, an organization cannot assess its exposure…

Enterprise Security

Question

New zero-day attacks are announced on a regular basis against a broad range of technology systems. Which of the following best practices should a security manager do to manage the risks of these attack vectors? (Select TWO).

Options

  • AEstablish an emergency response call tree.
  • BCreate an inventory of applications.
  • CBackup the router and firewall configurations.
  • DMaintain a list of critical systems.
  • EUpdate all network diagrams.

How the community answered

(34 responses)
  • A
    15% (5)
  • B
    74% (25)
  • C
    6% (2)
  • E
    6% (2)

Why each option

Managing zero-day risk requires knowing what you have - an application inventory identifies exposed software, and a critical systems list enables prioritized triage and response. Without knowing what is deployed and what is critical, an organization cannot assess its exposure to newly disclosed vulnerabilities.

AEstablish an emergency response call tree.

An emergency response call tree is a communication tool for after an incident is confirmed; it does not help assess or reduce the risk exposure from a new zero-day.

BCreate an inventory of applications.Correct

An application inventory maps every software package in use so that when a zero-day is announced, the security team can immediately determine whether any affected product is present in the environment and begin remediation or compensating controls.

CBackup the router and firewall configurations.

Backing up router and firewall configurations is a recovery practice and does not help identify exposure to a new vulnerability or prioritize response actions.

DMaintain a list of critical systems.Correct

A critical systems list allows the security manager to prioritize response efforts toward the assets whose compromise would cause the greatest business impact, ensuring limited resources are focused where a zero-day exploit would be most damaging.

EUpdate all network diagrams.

Updating network diagrams is a documentation activity that does not directly help a security manager assess which systems are vulnerable to a newly announced zero-day.

Concept tested: Asset inventory and critical system identification for zero-day risk management

Source: https://www.cisa.gov/known-exploited-vulnerabilities-catalog

Topics

#zero-day attacks#application inventory#critical systems#risk management

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice