CAS-002 · Question #94
After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The company has a standard…
The correct answer is B. Conduct a vulnerability assessment of the standard image and remediate findings. Conducting a vulnerability assessment of the standard system image identifies weaknesses in the baseline configuration before deployment, directly addressing the root cause of recurring malware attacks.
Question
After a recent outbreak of malware attacks, the Chief Information Officer (CIO) tasks the new security manager with determining how to keep these attacks from reoccurring. The company has a standard image for all laptops/workstations and uses a host-based firewall and anti-virus. Which of the following should the security manager suggest to INCREASE each system's security level?
Options
- AUpgrade all system's to use a HIPS and require daily anti-virus scans.
- BConduct a vulnerability assessment of the standard image and remediate findings.
- CUpgrade the existing NIDS to NIPS and deploy the system across all network segments.
- DRebuild the standard image and require daily anti-virus scans of all PCs and laptops.
How the community answered
(33 responses)- A9% (3)
- B76% (25)
- C12% (4)
- D3% (1)
Why each option
Conducting a vulnerability assessment of the standard system image identifies weaknesses in the baseline configuration before deployment, directly addressing the root cause of recurring malware attacks.
Upgrading to HIPS and increasing anti-virus scan frequency adds detection layers but does not identify or remediate the underlying vulnerabilities in the standard image that allowed the initial outbreak.
A vulnerability assessment of the standard image systematically identifies unpatched software, insecure configurations, and unnecessary services baked into the baseline, allowing the organization to harden the image before it is deployed to all endpoints. This proactive approach addresses the underlying attack vectors that malware exploits, rather than relying solely on reactive detection tools.
Upgrading NIDS to NIPS is a network-level control that can block known attack traffic but does not address vulnerabilities on individual host systems or the standard image itself.
Rebuilding the standard image without a prior vulnerability assessment and adding daily scans is reactive and does not guarantee the new image is hardened against the same vulnerabilities.
Concept tested: Vulnerability assessment of system baseline images
Source: https://csrc.nist.gov/publications/detail/sp/800-40/rev-4/final
Topics
Community Discussion
No community discussion yet for this question.