GCIH · Question #623
An incident handler concluded that a recent breach could have been prevented with a software patch. In their report they recommended the organization perform regular vulnerability scans, document…
The correct answer is C. Following up on post-incident recommendations. The organization failed to act on explicit post-incident recommendations to patch software, allowing the same class of vulnerability to cause a second breach six months later.
Question
An incident handler concluded that a recent breach could have been prevented with a software patch. In their report they recommended the organization perform regular vulnerability scans, document the findings and update software assets. Six months later the incident handler investigates a new breach and concludes the web server was infected due to an outdated version of a Content Management System (CMS). Based on this information, what part of the incident handling process does the organization need to improve?
Options
- ADisabling unused software to prevent infection
- BIdentifying and responding to incidents quickly
- CFollowing up on post-incident recommendations
- DMaintaining time-stamped logs of user activity
How the community answered
(22 responses)- A5% (1)
- B14% (3)
- C77% (17)
- D5% (1)
Why each option
The organization failed to act on explicit post-incident recommendations to patch software, allowing the same class of vulnerability to cause a second breach six months later.
Disabling unused software was not part of the recommendations made after the first incident, so it does not represent the gap the scenario is illustrating.
The question focuses on a preventable recurrence caused by known, unpatched vulnerabilities, not on the speed of detection or containment during either incident.
After the first incident, the handler documented specific remediation steps including regular vulnerability scanning and software updates. The second breach - caused by an unpatched CMS - demonstrates those recommendations were never implemented. Failing to close the loop on post-incident action items is a breakdown in the lessons-learned and follow-up phase of the incident handling lifecycle.
Maintaining time-stamped logs addresses evidence collection and forensic auditing, not the remediation gap that allowed the same class of vulnerability to persist unpatched.
Concept tested: Incident handling lessons learned and follow-up phase
Source: https://nvlpubs.nist.gov/nistpubs/SpecialPublications/NIST.SP.800-61r2.pdf
Topics
Community Discussion
No community discussion yet for this question.