CISM · Question #145
Which of the following actions will BEST resolve the root cause of a cyber incident involving unauthorized network access due to a critical vulnerability on a web server?
The correct answer is A. Improving the patching process. To best resolve the root cause of unauthorized access stemming from a critical web server vulnerability, improving the patching process is essential. This addresses the underlying flaw that allowed the incident to occur, preventing recurrence.
Question
Which of the following actions will BEST resolve the root cause of a cyber incident involving unauthorized network access due to a critical vulnerability on a web server?
Options
- AImproving the patching process
- BLocking accounts with unauthorized access
- CIsolating affected systems
- DTerminating malicious network connections
How the community answered
(35 responses)- A74% (26)
- B14% (5)
- C3% (1)
- D9% (3)
Why each option
To best resolve the root cause of unauthorized access stemming from a critical web server vulnerability, improving the patching process is essential. This addresses the underlying flaw that allowed the incident to occur, preventing recurrence.
The root cause of the incident is a critical vulnerability on the web server, which implies inadequate or delayed patching. Improving the patching process ensures that vulnerabilities are promptly identified and remediated, thereby preventing similar incidents in the future by eliminating the initial entry point.
Locking accounts addresses the symptoms of unauthorized access but does not fix the underlying critical vulnerability that enabled the compromise in the first place.
Isolating systems is a containment strategy during an incident but does not resolve the root cause vulnerability that led to the compromise.
Terminating connections is a containment action that stops active attacks but does not fix the critical vulnerability that allowed the connections to be established.
Concept tested: Cyber incident root cause analysis and remediation
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-vulnerabilities?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.