CAS-003 · Question #90
A completely new class of web-based vulnerabilities has been discovered. Claims have been made that all common web-based development frameworks are susceptible to attack. Proof-of- concept details…
The correct answer is A. Assess the reliability of the information source, likelihood of exploitability, and impact to hosted. The first thing you should do is verify the reliability of the claims. From there you can assess the likelihood of the vulnerability affecting your systems. If it is determined that your systems are likely to be affected by the exploit, you need to determine what impact an…
Question
A completely new class of web-based vulnerabilities has been discovered. Claims have been made that all common web-based development frameworks are susceptible to attack. Proof-of- concept details have emerged on the Internet. A security advisor within a company has been asked to provide recommendations on how to respond quickly to these vulnerabilities. Which of the following BEST describes how the security advisor should respond?
Options
- AAssess the reliability of the information source, likelihood of exploitability, and impact to hosted
- BHire an independent security consulting agency to perform a penetration test of the web servers.
- CReview vulnerability write-ups posted on the Internet. Respond to management with a
- DNotify all customers about the threat to their hosted data. Bring the web servers down into
How the community answered
(50 responses)- A54% (27)
- B6% (3)
- C28% (14)
- D12% (6)
Explanation
The first thing you should do is verify the reliability of the claims. From there you can assess the likelihood of the vulnerability affecting your systems. If it is determined that your systems are likely to be affected by the exploit, you need to determine what impact an attack will have on your hosted data. Now that you know what the impact will be, you can test the exploit by using the proof-of-concept code. That should help you determine your options for dealing with the threat
Topics
Community Discussion
No community discussion yet for this question.