Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy
A security analyst is investigating a potential compromise. Logs show that an attacker exploited a known vulnerability in an unpatched web server. The vulnerability had a CVSS Base Score of 9.8 (Critical) and was publicly disclosed three months prior. The organization's vulnerability management policy states that critical vulnerabilities must be patched within 7 days of discovery. What is the MOST likely reason this vulnerability led to a breach?
- AThe vulnerability was a zero-day exploit, making it impossible to patch.
- BThe attacker used a sophisticated, unknown attack technique.
- CThe organization failed in its vulnerability remediation process.
- DThe vulnerability was misclassified with an incorrect CVSS score.
Show answer & explanationAnswer & explanation
Correct answer: C. The organization failed in its vulnerability remediation process.
The scenario clearly states the vulnerability was 'known,' 'publicly disclosed three months prior,' and the server was 'unpatched.' This indicates a failure in the organization's remediation process to apply the necessary patch within the policy-mandated timeframe.
Why the other options are wrong
- A. The vulnerability was 'known' and 'publicly disclosed,' ruling out a zero-day exploit.
- B. The attacker exploited a 'known vulnerability,' indicating the technique was likely not unknown or overly sophisticated.
- D. The CVSS score was 9.8 (Critical), indicating it was correctly classified as requiring urgent attention, making misclassification unlikely to be the primary cause of the breach.
Vulnerability Remediation Failure
Vulnerability remediation failure occurs when identified security weaknesses are not addressed or fixed effectively within established timeframes, leading to continued exposure to risk.
- Can result from inadequate patching, misprioritization, or lack of resources.
- Often a critical breakdown in the vulnerability management lifecycle.
- Directly increases the likelihood of successful exploitation.
Memory trick: Breach from VULNERABILITY: Unpatched, Unknown, Misconfigured, Exploited.