CISSP · Question #1252
A breach investigation found a website was exploited through an open source component. What is the FIRST step in the process that could have prevented this breach?
The correct answer is D. Software inventory. The breach occurred due to an exploited open-source component. The FIRST step to prevent this is D. Software inventory, and here's why: CISSP Domain Alignment: Domain 2 (Asset Security) and Domain 8 (Software Development Security) emphasize maintaining a software inventory to tra
Question
Options
- AApplication whitelisting
- BWeb application firewall (WAF)
- CVulnerability remediation
- DSoftware inventory
How the community answered
(29 responses)- A3% (1)
- B7% (2)
- C17% (5)
- D72% (21)
Explanation
The breach occurred due to an exploited open-source component. The FIRST step to prevent this is D. Software inventory, and here's why: CISSP Domain Alignment: Domain 2 (Asset Security) and Domain 8 (Software Development Security) emphasize maintaining a software inventory to track all components (including open-source libraries). Without knowing what software is in use, vulnerabilities cannot be identified or managed.
Topics
Community Discussion
No community discussion yet for this question.