nerdexam
CompTIA

CAS-002 · Question #597

Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chief Information…

The correct answer is C. Patch the known issues and provide the patch to customers. Patching known vulnerabilities and distributing the patch to customers satisfies the top priorities of immediate security improvement and minimizing customer impact.

Enterprise Security

Question

Company XYZ has had repeated vulnerability exploits of a critical nature released to the company's flagship product. The product is used by a number of large customers. At the Chief Information Security Officer's (CISO's) request, the product manager now has to budget for a team of security consultants to introduce major product security improvements. Here is a list of improvements in order of priority: 1. A noticeable improvement in security posture immediately. 2. Fundamental changes to resolve systemic issues as an ongoing process 3. Improvements should be strategic as opposed to tactical 4. Customer impact should be minimized Which of the following recommendations is BEST for the CISO to put forward to the product manager?

Options

  • APatch the known issues and provide the patch to customers.
  • BPatch the known issues and provide the patch to customers.
  • CPatch the known issues and provide the patch to customers.
  • DStop active support of the product.

How the community answered

(44 responses)
  • A
    23% (10)
  • B
    7% (3)
  • C
    57% (25)
  • D
    14% (6)

Why each option

Patching known vulnerabilities and distributing the patch to customers satisfies the top priorities of immediate security improvement and minimizing customer impact.

APatch the known issues and provide the patch to customers.

Though textually identical to option C in this question, it is not identified as the best answer - the intended distinction likely relates to scope or process details that were lost in question formatting.

BPatch the known issues and provide the patch to customers.

Though textually identical to option C in this question, it is not identified as the best answer - the intended distinction likely relates to scope or process details that were lost in question formatting.

CPatch the known issues and provide the patch to customers.Correct

Issuing a patch for known exploited vulnerabilities provides an immediate and measurable improvement in security posture, directly satisfying priority one. Delivering the patch to customers minimizes their continued exposure, satisfying priority four, while the organization pursues longer-term systemic and strategic remediation efforts in parallel.

DStop active support of the product.

Stopping active support abandons existing customers to unpatched vulnerabilities, maximizes customer impact, and fails to address any of the four stated improvement priorities.

Concept tested: Vulnerability remediation and patch deployment prioritization

Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-40r4.pdf

Topics

#product security lifecycle#vulnerability management#strategic security#SDLC

Community Discussion

No community discussion yet for this question.

Full CAS-002 Practice