ETExamTower
Q8Processes

Refer to the exhibit. Based on the identified vulnerabilities, what is the next recommended mitigation step?

Question exhibit
← → navigate · a answer
Community votes
C
75% (3)
A
25% (1)
B
0% (0)
D
0% (0)
Discussion · 6
3
C is right
3
Agree. C is right.
1
Based on the detected vulnerabilities, the next recommended mitigation step is to remediate all vulnerabilities in descending Common Vulnerability Scoring System (CVSS) score order. Prioritizing vulnerabilities by their CVSS score is a common practice that lets organizations focus on fixing the most severe vulnerabilities first. Evaluating service disruption and the associated risk before prioritizing patches (option A) can be a time-consuming process that delays remediation of critical vulnerabilities. Performing root cause analysis for all detected vulnerabilities (option B) is also an important step, but it can be done alongside remediation efforts. Temporarily shutting down unnecessary services until patch deployment ends (option D) can reduce the attack surface, but it may not be practical in all cases, and it does not address the underlying vulnerabilities. Therefore, option C, remediate all vulnerabilities in descending CVSS score order, is the most appropriate next recommended mitigation step.
C 1
Selected Answer: C I would choose C, even though this is a practice that is not used anymore as other business-related considerations should be made, but it was the default action in the past.
A 1
Selected Answer: A ChatGPT: While CVSS is a useful tool, relying only on CVSS scores can result in less-than-ideal prioritization. Assessing the risk and impact to business services gives a more holistic approach to vulnerability management and remediation, helping you protect the most critical systems first.
C 1
Selected Answer: C The exhibit shows several critical vulnerabilities with high CVSS scores, including two scored at 10, which indicates maximum severity. In vulnerability management, especially when immediate exploitation is possible (for example, remote code execution like Shellshock), the best practice is to: Prioritize remediation based on CVSS score (Common Vulnerability Scoring System) Begin with the highest-risk vulnerabilities to reduce exposure quickly This approach aligns with security frameworks like NIST, CIS, and ISO/IEC 27001 for risk-based remediation.