CompTIA CySA+ (CS0-003)Reporting and CommunicationHard
A security analyst has identified a critical vulnerability in a third-party application used by the finance department. The vulnerability has a CVSS score of 9.8 and allows unauthenticated remote code execution. The analyst needs to communicate this to the finance department head and the vendor. Which of the following is the MOST appropriate initial step for communicating this information to ensure proper handling and prioritization?
- ASend an email directly to the vendor's support alias, cc'ing the finance department head.
- BCreate a detailed vulnerability report and schedule a meeting with the finance department head to explain the risks.
- CImmediately notify the incident response team and the CISO, then follow established vulnerability disclosure procedures.
- DPost an alert on the internal security dashboard for all employees to see, including the CVSS score.
Show answer & explanationAnswer & explanation
Correct answer: C. Immediately notify the incident response team and the CISO, then follow established vulnerability disclosure procedures.
A critical vulnerability with unauthenticated RCE potential requires immediate escalation to the incident response team and CISO due to its high impact and urgency. Following established vulnerability disclosure procedures ensures a coordinated and responsible approach, including communication with the vendor and affected departments.
Why the other options are wrong
- A. Directly emailing the vendor and finance without internal coordination might bypass established protocols and lead to unmanaged disclosure.
- B. Scheduling a meeting with only the finance head might delay immediate action and lacks the broader organizational response needed for a critical vulnerability.
- D. Publicly posting a critical vulnerability on an internal dashboard for all employees is an insecure practice that could lead to unauthorized exploitation and panic.
Vulnerability Disclosure
The process of identifying, reporting, and remediating security vulnerabilities in a controlled and responsible manner, often involving coordination with vendors.
- Prioritize immediate internal escalation for critical findings.
- Follow established procedures for vendor communication.
- Aim for coordinated remediation and public disclosure (if applicable).
Memory trick: Critical flaw? Alert IR & CISO first, then follow the disclosure path.