nerdexam
CompTIA

CV0-002 · Question #260

A new vulnerability has been announced which affects several critical VM guests, but no patch is available. Which of the following can the administrator perform to mitigate this risk prior to a patch

The correct answer is B. Apply all available software patches to VM guests and VM hosts. Despite no specific patch for a newly announced vulnerability, applying all other available software patches to VM guests and hosts is a crucial general security measure to reduce the overall attack surface and mitigate related risks.

Security

Question

A new vulnerability has been announced which affects several critical VM guests, but no patch is available. Which of the following can the administrator perform to mitigate this risk prior to a patch being released?

Options

  • AInstall and update antivirus software on all workstations
  • BApply all available software patches to VM guests and VM hosts
  • CDisable the affected service if it is found to be unnecessary
  • DCluster all affected VM guests and implement resource pooling

How the community answered

(27 responses)
  • A
    7% (2)
  • B
    74% (20)
  • C
    4% (1)
  • D
    15% (4)

Why each option

Despite no specific patch for a newly announced vulnerability, applying all other available software patches to VM guests and hosts is a crucial general security measure to reduce the overall attack surface and mitigate related risks.

AInstall and update antivirus software on all workstations

Installing and updating antivirus software on workstations is a general security measure for endpoints, not a direct mitigation strategy for a server-side VM guest vulnerability.

BApply all available software patches to VM guests and VM hostsCorrect

Even if a specific patch for the new vulnerability is not yet available, applying all other existing and available software patches to both VM guests and their underlying hosts is a critical security best practice. This action helps to eliminate other known vulnerabilities, harden the systems, and reduce the overall attack surface, making it more difficult for attackers to exploit the new, unpatched vulnerability.

CDisable the affected service if it is found to be unnecessary

Disabling the affected service is a valid mitigation strategy if the service is unnecessary, but applying other available patches (Option B) is a broader, more fundamental security measure that should always be performed as a general hardening step.

DCluster all affected VM guests and implement resource pooling

Clustering VM guests and implementing resource pooling are primarily for high availability and resource management, not direct mitigation for a software vulnerability.

Concept tested: General security patching and vulnerability mitigation

Source: https://learn.microsoft.com/en-us/azure/security/fundamentals/patch-management

Topics

#Vulnerability management#Patch management#Risk mitigation#VM security

Community Discussion

No community discussion yet for this question.

Full CV0-002 Practice