CS0-003 · Question #400
During an internal code review, software called "ACE" was discovered to have a vulnerability that allows the execution of arbitrary code. The vulnerability is in a legacy, third-party vendor…
The correct answer is D. Develop a compensating control until the issue can be fixed permanently. A compensating control is an alternative measure that provides a similar level of protection as the original control, but is used when the original control is not feasible or cost-effective. In this case, the CISO should develop a compensating control to mitigate the risk of…
Question
During an internal code review, software called "ACE" was discovered to have a vulnerability that allows the execution of arbitrary code. The vulnerability is in a legacy, third-party vendor resource that is used by the ACE software. ACE is used worldwide and is essential for many businesses in this industry. Developers informed the Chief Information Security Officer that removal of the vulnerability will take time. Which of the following is the first action to take?
Options
- ALook for potential loCs in the company.
- BInform customers of the vulnerability.
- CRemove the affected vendor resource from the ACE software.
- DDevelop a compensating control until the issue can be fixed permanently.
How the community answered
(25 responses)- A16% (4)
- B12% (3)
- C4% (1)
- D68% (17)
Explanation
A compensating control is an alternative measure that provides a similar level of protection as the original control, but is used when the original control is not feasible or cost-effective. In this case, the CISO should develop a compensating control to mitigate the risk of the vulnerability in the ACE software, such as implementing additional monitoring, firewall rules, or encryption, until the issue can be fixed permanently by the developers.
Topics
Community Discussion
No community discussion yet for this question.