CAS-003 · Question #466
A networking administrator was recently promoted to security administrator in an organization that handles highly sensitive data. The Chief Information Security Officer (CISO) has just asked for all…
The correct answer is A. CVE database C. Security vendor pages G. Verified security forums. For researching a zero-day vulnerability in a specific application server, the CVE database (A), security vendor pages (C), and verified security forums (G) are the three most relevant sources. The CVE database provides structured records of vulnerabilities in the affected…
Question
A networking administrator was recently promoted to security administrator in an organization that handles highly sensitive data. The Chief Information Security Officer (CISO) has just asked for all IT security personnel to review a zero-day vulnerability and exploit for specific application servers to help mitigate the organization's exposure to that risk. Which of the following should the new security administrator review to gain more information? (Choose three.)
Options
- ACVE database
- BRecent security industry conferences
- CSecurity vendor pages
- DKnown vendor threat models
- ESecure routing metrics
- FServer's vendor documentation
- GVerified security forums
- HNetFlow analytics
How the community answered
(48 responses)- A94% (45)
- E2% (1)
- H4% (2)
Explanation
For researching a zero-day vulnerability in a specific application server, the CVE database (A), security vendor pages (C), and verified security forums (G) are the three most relevant sources. The CVE database provides structured records of vulnerabilities in the affected software, including related CVEs that provide context about the attack surface even if the specific zero-day is not yet listed. Security vendor pages (Palo Alto, CrowdStrike, Microsoft, etc.) publish real-time threat intelligence, security advisories, and mitigation guidance specific to active exploits. Verified security forums (SANS ISC, Bugtraq, security researcher communities) are often where zero-day details and proof-of-concept information first surface. Security conferences (B) are not immediately accessible; vendor threat models (D) predate new discoveries; routing metrics (E) and NetFlow analytics (H) are operational data, not threat research sources; vendor documentation (F) covers product features, not emerging vulnerabilities.
Topics
Community Discussion
No community discussion yet for this question.