CAS-005 · Question #106
A security team is responding to malicious activity and needs to determine the scope of impact. The malicious activity appears to affect a certain version of an application used by the organization…
The correct answer is C. Reviewing the asset inventory. Reviewing the asset inventory allows the security team to identify all instances of the affected application versions within the organization. By knowing which systems are running the vulnerable versions, the team can assess the full scope of the impact, determine which systems…
Question
A security team is responding to malicious activity and needs to determine the scope of impact. The malicious activity appears to affect a certain version of an application used by the organization. Which of the following actions best enables the team to determine the scope of impact?
Options
- APerforming a port scan
- BInspecting egress network traffic
- CReviewing the asset inventory
- DAnalyzing user behavior
How the community answered
(45 responses)- A2% (1)
- B9% (4)
- C84% (38)
- D4% (2)
Explanation
Reviewing the asset inventory allows the security team to identify all instances of the affected application versions within the organization. By knowing which systems are running the vulnerable versions, the team can assess the full scope of the impact, determine which systems might be compromised, and prioritize them for further investigation and remediation.
Community Discussion
No community discussion yet for this question.