SECOPS-PRO · Question #73
A critical zero-day vulnerability is publicly disclosed in a widely used web server. Your organization's incident response plan dictates immediate action to identify potential exploitation attempts. Y
The correct answer is B. Leveraging Unit 42's rapid vulnerability research and exploit intelligence to identify specific exploit. A zero-day vulnerability requires immediate, targeted action and deep understanding of potential exploits. Unit 42 excels in rapid vulnerability research and exploit intelligence, often providing detailed analysis of how vulnerabilities are being weaponized in the wild. This inte
Question
A critical zero-day vulnerability is publicly disclosed in a widely used web server. Your organization's incident response plan dictates immediate action to identify potential exploitation attempts. You have Palo Alto Networks NGFWs, access to WildFire, and subscribe to Unit 42 threat intelligence. Furthermore, your team frequently uses VirusTotal for initial reconnaissance. To swiftly identify and contain potential exploitation attempts, which of the following combined strategies offers the best immediate response capability and long-term intelligence gathering?
Options
- AProactively blocking all traffic to the affected web server and submitting its logs to VirusTotal for
- BLeveraging Unit 42's rapid vulnerability research and exploit intelligence to identify specific exploit
- CDisabling the vulnerable web server entirely until a patch is released, and reviewing historical
- DMonitoring public forums and social media for mentions of the vulnerability and applying generic
- EFocusing solely on endpoint detection and response (EDR) alerts, as web server exploitation is
How the community answered
(22 responses)- A14% (3)
- B73% (16)
- D9% (2)
- E5% (1)
Explanation
A zero-day vulnerability requires immediate, targeted action and deep understanding of potential exploits. Unit 42 excels in rapid vulnerability research and exploit intelligence, often providing detailed analysis of how vulnerabilities are being weaponized in the wild. This intelligence is crucial for creating specific, effective threat prevention rules on NGFWs. WildFire can then be used to analyze any novel payloads or post-exploitation tools observed, providing real-time signatures. This combined approach allows for proactive network-level defense based on expert intelligence and dynamic analysis of new threats.
Topics
Community Discussion
No community discussion yet for this question.