CISA · Question #387
A zero-day vulnerability with a critical severity score has been published for a core business application. Which of the following should be done FIRST to address this vulnerability?
The correct answer is A. Identify the version of software the organization is using. The first step to address a zero-day vulnerability is to identify the version of the software the organization is using. This ensures that the vulnerability is applicable to the specific version in use and helps in determining the appropriate remediation steps, such as finding av
Question
A zero-day vulnerability with a critical severity score has been published for a core business application. Which of the following should be done FIRST to address this vulnerability?
Options
- AIdentify the version of software the organization is using
- BInitiate the organization's incident response plan
- CWork with the vendor to deploy patches in the production environment
- DPropose risk acceptance until a patch is deployed
How the community answered
(29 responses)- A79% (23)
- B10% (3)
- C3% (1)
- D7% (2)
Explanation
The first step to address a zero-day vulnerability is to identify the version of the software the organization is using. This ensures that the vulnerability is applicable to the specific version in use and helps in determining the appropriate remediation steps, such as finding available patches or mitigating controls. Once the version is identified, the organization can proceed with patch deployment, risk assessment, or incident response as needed.
Topics
Community Discussion
No community discussion yet for this question.