CompTIA CySA+ (CS0-003)Vulnerability ManagementMedium
A security analyst is investigating an incident where a critical application server was compromised. The attacker exploited a known vulnerability in an unpatched third-party library used by the application. The organization had a policy to apply patches within 30 days of release, but this specific library's patch was overlooked. What type of vulnerability management failure does this scenario represent?
- AIneffective patch management
- BPoor secure coding practices
- CLack of asset discovery
- DInsufficient vulnerability scanning
Show answer & explanationAnswer & explanation
Correct answer: A. Ineffective patch management
The scenario explicitly states that the attacker exploited a 'known vulnerability in an unpatched third-party library' and that a 'patch was overlooked' despite a patching policy. This directly points to a failure in the patch management process, which is a key component of vulnerability management.
Why the other options are wrong
- B. Poor secure coding practices relate to the initial introduction of vulnerabilities during development, not the failure to patch existing ones in third-party components.
- C. Lack of asset discovery would mean the server or application wasn't known to exist, which isn't indicated here.
- D. Insufficient vulnerability scanning might have missed the vulnerability initially, but the problem here is not applying a known patch, implying the vulnerability was (or should have been) known.
Patch Management
Patch management is the process of identifying, acquiring, testing, and applying software updates (patches) to systems to fix bugs, improve performance, and, crucially, address security vulnerabilities.
- Crucial for reducing the attack surface by remediating known flaws.
- Involves regular scanning, prioritization, testing, and deployment of patches.
- Failure can lead to exploitation of unpatched vulnerabilities.
Memory trick: Discover, Assess, Prioritize, Remediate, Verify (DAPRV) – the cycle never ends.