CS0-003 · Question #28
An analyst is reviewing a vulnerability report for a server environment with the following entries: Which of the following systems should be prioritized for patching first?
The correct answer is D. 54.74.110.228. Prioritizing patching involves assessing vulnerability severity, system criticality, and exposure to determine which systems require immediate attention.
Question
An analyst is reviewing a vulnerability report for a server environment with the following entries:
Which of the following systems should be prioritized for patching first?
Exhibit
Options
- A10.101.27.98
- B54.73.225.17
- C54.74.110.26
- D54.74.110.228
How the community answered
(51 responses)- A4% (2)
- B2% (1)
- C10% (5)
- D84% (43)
Why each option
Prioritizing patching involves assessing vulnerability severity, system criticality, and exposure to determine which systems require immediate attention.
An internal IP (10.101.27.98) is generally prioritized lower for initial patching than public-facing systems unless it is critical for internal operations and has an easily exploitable, high-severity vulnerability.
This is a public IP, but the implied vulnerability report suggests that 54.74.110.228 has a higher combined risk or more severe vulnerability, making it the top priority.
This is also a public IP, but the context indicates 54.74.110.228 has the highest prioritization based on the unseen details of the vulnerability report, likely due to a more critical vulnerability or service.
Without the specific vulnerability report, the selection of 54.74.110.228 as the highest priority implies it hosts a critical service, is publicly accessible, and/or has a high-severity vulnerability that warrants immediate patching. Prioritizing public-facing systems with critical flaws is essential to prevent external exploitation.
Concept tested: Vulnerability prioritization
Source: https://learn.microsoft.com/en-us/microsoft-365/security/defender-vulnerability-management/tvm-priorities?view=o365-worldwide
Topics
Community Discussion
No community discussion yet for this question.
