CISSP · Question #390
Which of the following is an accurate statement when an assessment results in the discovery of vulnerabilities in a critical network component?
The correct answer is A. The fact that every other host is sufficiently hardened does not change the fact frat the network is. When a critical network component has vulnerabilities, the entire network's security is compromised regardless of how well other hosts are hardened, because a critical component serves as a foundational dependency for network integrity.
Question
Which of the following is an accurate statement when an assessment results in the discovery of vulnerabilities in a critical network component?
Options
- AThe fact that every other host is sufficiently hardened does not change the fact frat the network is
- BThere is little likelihood that the entire network is being placed at a significant risk of attack.
- CA second assessment should immediately be performed after all vulnerabilities are corrected.
- DThere is a low possibility that any adjacently connected components have been compromised by
How the community answered
(55 responses)- A73% (40)
- B16% (9)
- C7% (4)
- D4% (2)
Why each option
When a critical network component has vulnerabilities, the entire network's security is compromised regardless of how well other hosts are hardened, because a critical component serves as a foundational dependency for network integrity.
A critical network component acts as a foundational element whose vulnerabilities can undermine the security of the entire network. Even if every other host is fully hardened, an attacker exploiting a vulnerability in a critical component (such as a core router, firewall, or authentication server) can potentially bypass or nullify those other security controls. The security of a network is only as strong as its weakest critical link.
This is incorrect because vulnerabilities in a critical network component significantly increase risk across the entire network, not reduce it - critical components often handle traffic or authentication for many other systems.
While re-assessment after remediation is a best practice, it is not the most accurate immediate statement about the impact of discovering vulnerabilities in a critical component; the priority statement concerns the risk posed, not the remediation workflow.
This is incorrect because a compromised critical network component actually increases the likelihood that adjacently connected components have been or could be compromised, not decreases it, due to the central role critical components play in network traffic and trust relationships.
Concept tested: Impact of vulnerabilities in critical network components
Source: https://csrc.nist.gov/publications/detail/sp/800-115/final
Topics
Community Discussion
No community discussion yet for this question.