GPEN · Question #396
A client with 7200 employees in 14 cities (all connected via high speed WAN connections) has suffered a major external security breach via a desktop which cost them more than SI 72.000 and the loss…
The correct answer is C. The client should hire more people to catch up on patches. When a vulnerability scan uncovers tens of thousands of unpatched issues across thousands of endpoints, scaling remediation capacity by hiring additional staff addresses the immediate need to work through the backlog.
Question
A client with 7200 employees in 14 cities (all connected via high speed WAN connections) has suffered a major external security breach via a desktop which cost them more than SI 72.000 and the loss of a high profile client. They ask you to perform a desktop vulnerability assessment to identify everything that needs to be patched. Using Nessus you find tens of thousands of vulnerabilities that need to be patched. In the report you find workstations running several Windows OS versions and service pack levels, anti-virus software from multiple vendors several major browser versions and different versions of Acrobat Reader. Which of the following recommendations should you provide with the report?
Options
- AThe client should standardize their desktop software
- BThe client should eliminate workstations to reduce workload
- CThe client should hire more people to catch up on patches
- DThe client should perform monthly vulnerability assessments
How the community answered
(37 responses)- A8% (3)
- B14% (5)
- C73% (27)
- D5% (2)
Why each option
When a vulnerability scan uncovers tens of thousands of unpatched issues across thousands of endpoints, scaling remediation capacity by hiring additional staff addresses the immediate need to work through the backlog.
Standardizing desktop software is a valid long-term preventive control but does not address the immediate need to remediate the tens of thousands of vulnerabilities already discovered and documented.
Eliminating workstations would reduce business operations and is not a proportionate or viable response to a vulnerability remediation requirement.
With 7,200 endpoints running mixed OS versions, multiple AV vendors, and varied browser and plugin versions generating tens of thousands of vulnerabilities, the immediate remediation gap requires sufficient personnel to execute patching at that scale. Hiring more staff directly increases the capacity needed to work through the critical vulnerability backlog identified by the assessment.
Monthly vulnerability assessments improve ongoing visibility but do not remediate the existing backlog of discovered vulnerabilities identified in the current report.
Concept tested: Vulnerability remediation recommendations for enterprise environments
Source: https://csrc.nist.gov/publications/detail/sp/800-40/rev-4/final
Topics
Community Discussion
No community discussion yet for this question.