Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementHard

A security team has identified a zero-day vulnerability affecting a critical, internet-facing application. There is no patch available, and the vulnerability is actively being exploited in the wild. The team decides to immediately deploy an intrusion prevention system (IPS) rule to block known attack signatures related to this exploit and implement a temporary Web Application Firewall (WAF) rule to filter malicious requests. What is the primary goal of these actions in the context of vulnerability remediation?

  1. ATo accept the risk until a permanent patch is released.
  2. BTo transfer the risk to a third-party vendor or insurance.
  3. CTo eliminate the vulnerability from the system.
  4. DTo mitigate the risk of exploitation by implementing compensating controls.
Show answer & explanation

Correct answer: D. To mitigate the risk of exploitation by implementing compensating controls.

Since no patch is available (zero-day), the vulnerability cannot be eliminated immediately. Deploying IPS and WAF rules are compensating controls designed to reduce the *likelihood* of the vulnerability being successfully exploited, thereby mitigating the risk, not eliminating it or accepting it.

Why the other options are wrong

  • A. Accepting the risk means taking no action; deploying IPS/WAF rules is an active measure to reduce risk.
  • B. Transferring risk involves shifting responsibility (e.g., insurance), which is not what these technical controls do.
  • C. Eliminating the vulnerability requires a patch or code change, which is not available for a zero-day.

Compensating Controls

Security controls implemented to provide an alternative or temporary measure of protection when a primary control is not feasible or effective.

  • Reduces risk when direct remediation is not possible.
  • Often temporary until a permanent fix is available.
  • Examples: WAF rules, IPS signatures, network segmentation.

Memory trick: Zero-Day, Mitigate Today.

More Vulnerability Management questions