SECOPS-PRO · Question #65
An organization is using a bespoke vulnerability management system that integrates with Palo Alto Networks Panorama for firewall rule management and XSOAR for incident orchestration. A new zero-day vu
The correct answer is B. Leveraging external threat intelligence feeds (e.g., Unit 42, CISA KEV) to confirm active. Prioritizing a zero-day vulnerability goes far beyond its static CVSS score or the number of affected systems. Option B outlines a comprehensive, dynamic approach: 1) Active Exploitation Confirmation: External threat intelligence (like CISA KEV or Unit 42 reports) indicating acti
Question
An organization is using a bespoke vulnerability management system that integrates with Palo Alto Networks Panorama for firewall rule management and XSOAR for incident orchestration. A new zero-day vulnerability (CVE-2023-XXXX) affecting a critical web application is disclosed. The vulnerability management system flags all instances of this application. For effective incident categorization and prioritization, what dynamic attributes or processes are crucial to incorporate, going beyond mere vulnerability detection?
Options
- AThe CVSS score of the CVE and the number of affected instances. While important, these are
- BLeveraging external threat intelligence feeds (e.g., Unit 42, CISA KEV) to confirm active
- CAssigning all alerts related to CVE-2023-XXXX to the highest priority, irrespective of whether the
- DPrioritizing remediation based solely on the operating system of the affected server, as OS-level
- EIgnoring the vulnerability until a patch is released, as immediate action is often disruptive.
How the community answered
(64 responses)- A11% (7)
- B81% (52)
- C2% (1)
- D2% (1)
- E5% (3)
Explanation
Prioritizing a zero-day vulnerability goes far beyond its static CVSS score or the number of affected systems. Option B outlines a comprehensive, dynamic approach: 1) Active Exploitation Confirmation: External threat intelligence (like CISA KEV or Unit 42 reports) indicating active exploitation in the wild immediately elevates the threat. 2) Correlated Network Activity: Analyzing Palo Alto Networks firewall logs or other network telemetry for unusual traffic patterns (e.g., specific HTTP requests, C2 communications) that align with known exploitation attempts for that CVE provides high-fidelity in-house detection. 3) Business Impact Assessment: Understanding the criticality of the specific web application (e.g., public- facing, handles sensitive customer data, critical business function) is paramount. Combining these three dynamic factors allows for truly informed categorization (e.g., 'Active Zero- Day Exploitation on Crown Jewel Asset') and prioritization (e.g., 'Critical - Immediate Containment'). Options A, C, D, and E represent static, overly broad, or negligent approaches.
Topics
Community Discussion
No community discussion yet for this question.