nerdexam
CompTIA

CAS-003 · Question #466

A networking administrator was recently promoted to security administrator in an organization that handles highly sensitive data. The Chief Information Security Officer (CISO) has just asked for all…

The correct answer is A. CVE database C. Security vendor pages G. Verified security forums. For researching a zero-day vulnerability in a specific application server, the CVE database (A), security vendor pages (C), and verified security forums (G) are the three most relevant sources. The CVE database provides structured records of vulnerabilities in the affected…

Research, Development and Collaboration

Question

A networking administrator was recently promoted to security administrator in an organization that handles highly sensitive data. The Chief Information Security Officer (CISO) has just asked for all IT security personnel to review a zero-day vulnerability and exploit for specific application servers to help mitigate the organization's exposure to that risk. Which of the following should the new security administrator review to gain more information? (Choose three.)

Options

  • ACVE database
  • BRecent security industry conferences
  • CSecurity vendor pages
  • DKnown vendor threat models
  • ESecure routing metrics
  • FServer's vendor documentation
  • GVerified security forums
  • HNetFlow analytics

How the community answered

(48 responses)
  • A
    94% (45)
  • E
    2% (1)
  • H
    4% (2)

Explanation

For researching a zero-day vulnerability in a specific application server, the CVE database (A), security vendor pages (C), and verified security forums (G) are the three most relevant sources. The CVE database provides structured records of vulnerabilities in the affected software, including related CVEs that provide context about the attack surface even if the specific zero-day is not yet listed. Security vendor pages (Palo Alto, CrowdStrike, Microsoft, etc.) publish real-time threat intelligence, security advisories, and mitigation guidance specific to active exploits. Verified security forums (SANS ISC, Bugtraq, security researcher communities) are often where zero-day details and proof-of-concept information first surface. Security conferences (B) are not immediately accessible; vendor threat models (D) predate new discoveries; routing metrics (E) and NetFlow analytics (H) are operational data, not threat research sources; vendor documentation (F) covers product features, not emerging vulnerabilities.

Topics

#zero-day vulnerabilities#threat intelligence#CVE database#security research sources

Community Discussion

No community discussion yet for this question.

Full CAS-003 Practice