CS0-003 · Question #646
A security analyst IS comparing the results of the past and current active credentialed vulnerability scans: Past scan: Current scan: Which of the following should the analyst do next?
The correct answer is B. Inform management about the risk that the company's assets will be used to perform attacks. The current scan shows that a previously low-severity SSL vulnerability has increased to a high- severity (9.1) issue with potential information disclosure. This means the organization now faces a significantly greater risk than before. Management must be informed because the…
Question
A security analyst IS comparing the results of the past and current active credentialed vulnerability scans:
Past scan:
Current scan:
Which of the following should the analyst do next?
Exhibits
Options
- ATry to avoid a data leak by immediately creating a self-signed TLS certificate to patch the NTP
- BInform management about the risk that the company's assets will be used to perform attacks.
- CCreate a new entry on the risk register saying that all significant risks have been mitigated.
- DRequest an unauthenticated scan to confirm that vulnerabilities have been patched.
How the community answered
(44 responses)- A9% (4)
- B50% (22)
- C27% (12)
- D14% (6)
Explanation
The current scan shows that a previously low-severity SSL vulnerability has increased to a high- severity (9.1) issue with potential information disclosure. This means the organization now faces a significantly greater risk than before. Management must be informed because the company's assets could be leveraged in attacks or suffer data exposure, and leadership needs awareness to prioritize remediation.
Topics
Community Discussion
No community discussion yet for this question.

