CRISC · Question #12
Which of the following would BEST mitigate the ongoing risk associated with operating system (OS) vulnerabilities?
The correct answer is C. Evaluate permanent fixes such as patches and upgrades. To best mitigate ongoing operating system vulnerabilities, organizations should proactively evaluate and apply permanent fixes like patches and upgrades.
Question
Which of the following would BEST mitigate the ongoing risk associated with operating system (OS) vulnerabilities?
Options
- ATemporarily mitigate the OS vulnerabilities
- BDocument and implement a patching process
- CEvaluate permanent fixes such as patches and upgrades
- DIdentify the vulnerabilities and applicable OS patches
How the community answered
(29 responses)- A17% (5)
- B7% (2)
- C45% (13)
- D31% (9)
Why each option
To best mitigate ongoing operating system vulnerabilities, organizations should proactively evaluate and apply permanent fixes like patches and upgrades.
Temporarily mitigating OS vulnerabilities provides only short-term protection and does not address the ongoing nature of the risk or the underlying cause.
Documenting and implementing a patching process establishes the framework for mitigation but does not, by itself, perform the direct technical action of evaluating and applying the fixes that reduce the vulnerability.
Evaluating permanent fixes such as patches and upgrades is the best way to mitigate ongoing OS vulnerabilities because these are the definitive technical solutions that address the root cause of the vulnerabilities. This process ensures that the most effective and stable updates are identified and prepared for deployment, thereby reducing the system's attack surface and exposure over time.
Identifying vulnerabilities and applicable patches is a crucial preliminary step but does not constitute mitigation; it merely informs the subsequent actions needed to reduce the risk.
Concept tested: OS Vulnerability Remediation
Source: https://nvlpubs.nist.gov/nistpubs/Legacy/SP/nistspecialpublication800-40r3.pdf
Topics
Community Discussion
No community discussion yet for this question.