CAS-002 · Question #775
A completely new class of web-based vulnerabilities has been discovered. Claims have been made that all common web-based development frameworks are susceptible to attack. Proof-of- concept details…
The correct answer is A. Assess the reliability of the information source, likelihood of exploitability, and impact to hosted. When a newly discovered vulnerability class is reported, the first step is a structured risk evaluation - assessing source credibility, exploitability, and business impact - before taking any reactive action. This avoids overreaction to unverified claims while ensuring genuine…
Question
A completely new class of web-based vulnerabilities has been discovered. Claims have been made that all common web-based development frameworks are susceptible to attack. Proof-of- concept details have emerged on the Internet. A security advisor within a company has been asked to provide recommendations on how to respond quickly to these vulnerabilities. Which of the following BEST describes how the security advisor should respond?
Options
- AAssess the reliability of the information source, likelihood of exploitability, and impact to hosted
- BHire an independent security consulting agency to perform a penetration test of the web servers.
- CReview vulnerability write-ups posted on the Internet. Respond to management with a
- DNotify all customers about the threat to their hosted data. Bring the web servers down into
How the community answered
(53 responses)- A66% (35)
- B9% (5)
- C21% (11)
- D4% (2)
Why each option
When a newly discovered vulnerability class is reported, the first step is a structured risk evaluation - assessing source credibility, exploitability, and business impact - before taking any reactive action. This avoids overreaction to unverified claims while ensuring genuine threats receive prompt attention.
Assessing the reliability of the information source prevents costly responses to false or exaggerated claims, while evaluating likelihood of exploitability and impact allows the organization to prioritize its response proportionally to actual risk. This structured triage aligns with vulnerability management best practices and ensures that remediation decisions are evidence-based rather than reactive to unverified proof-of-concept reports.
Immediately hiring a penetration testing firm is premature and costly before the threat has been validated and scoped; penetration testing confirms exploitability but is not the first response step when basic triage has not yet occurred.
Relying solely on Internet write-ups for vulnerability information without assessing source credibility risks acting on inaccurate or incomplete data, which could lead to misdirected remediation efforts.
Taking web servers offline and notifying all customers before completing a risk assessment is a disproportionate response that causes unnecessary business disruption and reputational harm if the threat turns out to be overstated or inapplicable.
Concept tested: Vulnerability risk triage and response prioritization
Source: https://www.first.org/cvss/specification-document
Topics
Community Discussion
No community discussion yet for this question.