nerdexam
Isaca

CISM · Question #145

Which of the following actions will BEST resolve the root cause of a cyber incident involving unauthorized network access due to a critical vulnerability on a web server?

The correct answer is A. Improving the patching process. To best resolve the root cause of unauthorized access stemming from a critical web server vulnerability, improving the patching process is essential. This addresses the underlying flaw that allowed the incident to occur, preventing recurrence.

Submitted by kev92· Apr 18, 2026Information Security Incident Management

Question

Which of the following actions will BEST resolve the root cause of a cyber incident involving unauthorized network access due to a critical vulnerability on a web server?

Options

  • AImproving the patching process
  • BLocking accounts with unauthorized access
  • CIsolating affected systems
  • DTerminating malicious network connections

How the community answered

(35 responses)
  • A
    74% (26)
  • B
    14% (5)
  • C
    3% (1)
  • D
    9% (3)

Why each option

To best resolve the root cause of unauthorized access stemming from a critical web server vulnerability, improving the patching process is essential. This addresses the underlying flaw that allowed the incident to occur, preventing recurrence.

AImproving the patching processCorrect

The root cause of the incident is a critical vulnerability on the web server, which implies inadequate or delayed patching. Improving the patching process ensures that vulnerabilities are promptly identified and remediated, thereby preventing similar incidents in the future by eliminating the initial entry point.

BLocking accounts with unauthorized access

Locking accounts addresses the symptoms of unauthorized access but does not fix the underlying critical vulnerability that enabled the compromise in the first place.

CIsolating affected systems

Isolating systems is a containment strategy during an incident but does not resolve the root cause vulnerability that led to the compromise.

DTerminating malicious network connections

Terminating connections is a containment action that stops active attacks but does not fix the critical vulnerability that allowed the connections to be established.

Concept tested: Cyber incident root cause analysis and remediation

Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-vulnerabilities?view=o365-worldwide

Topics

#Root Cause Analysis#Incident Remediation#Vulnerability Management#Patch Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice