nerdexam
Isaca

CISA · Question #387

A zero-day vulnerability with a critical severity score has been published for a core business application. Which of the following should be done FIRST to address this vulnerability?

The correct answer is A. Identify the version of software the organization is using. The first step to address a zero-day vulnerability is to identify the version of the software the organization is using. This ensures that the vulnerability is applicable to the specific version in use and helps in determining the appropriate remediation steps, such as finding av

Submitted by noor.lb· Apr 18, 2026Protection of Information Assets

Question

A zero-day vulnerability with a critical severity score has been published for a core business application. Which of the following should be done FIRST to address this vulnerability?

Options

  • AIdentify the version of software the organization is using
  • BInitiate the organization's incident response plan
  • CWork with the vendor to deploy patches in the production environment
  • DPropose risk acceptance until a patch is deployed

How the community answered

(29 responses)
  • A
    79% (23)
  • B
    10% (3)
  • C
    3% (1)
  • D
    7% (2)

Explanation

The first step to address a zero-day vulnerability is to identify the version of the software the organization is using. This ensures that the vulnerability is applicable to the specific version in use and helps in determining the appropriate remediation steps, such as finding available patches or mitigating controls. Once the version is identified, the organization can proceed with patch deployment, risk assessment, or incident response as needed.

Topics

#Vulnerability Management#Security Incident Response#Asset Identification

Community Discussion

No community discussion yet for this question.

Full CISA Practice