nerdexam
Isaca

CISM · Question #174

A security firm publicizes a critical security flaw in the encryption protocol for an external facing web page. Which of the following should the information security manager do FIRST?

The correct answer is C. Perform a risk assessment.. Before taking remediation action, the information security manager must perform a risk assessment to determine whether the organization's systems are actually affected, the severity of exposure given the organization's specific context, and the most appropriate response. A disclo

Submitted by jian89· Apr 18, 2026Information Security Risk Management

Question

A security firm publicizes a critical security flaw in the encryption protocol for an external facing web page. Which of the following should the information security manager do FIRST?

Options

  • ARemediate the vulnerability.
  • BRotate the encryption key.
  • CPerform a risk assessment.
  • DActivate the incident response team.

How the community answered

(30 responses)
  • A
    3% (1)
  • B
    13% (4)
  • C
    77% (23)
  • D
    7% (2)

Explanation

Before taking remediation action, the information security manager must perform a risk assessment to determine whether the organization's systems are actually affected, the severity of exposure given the organization's specific context, and the most appropriate response. A disclosed vulnerability in a protocol does not automatically mean the organization is vulnerable - they may use a different version, have compensating controls, or the affected component may not be in scope. Acting on remediation (A) or activating incident response (D) before assessing actual exposure could waste resources or cause unnecessary disruption. Rotating encryption keys (B) may not address the underlying flaw. Risk assessment first ensures the response is targeted, proportionate, and informed.

Topics

#Risk Assessment#Vulnerability Management#Prioritization#Security Program Management

Community Discussion

No community discussion yet for this question.

Full CISM Practice