Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium
A security analyst is reviewing a vulnerability report for a critical web application. The report highlights a SQL Injection vulnerability that could allow an attacker to extract sensitive data from the database. The development team states they cannot immediately patch the vulnerability due to a complex release cycle. To address the immediate risk, they propose implementing input validation and parameterized queries in the application layer. What type of vulnerability management action is this?
- AFull Remediation
- BWorkaround
- CFalse Positive
- DRisk Acceptance
Show answer & explanationAnswer & explanation
Correct answer: B. Workaround
Implementing input validation and parameterized queries acts as a temporary or partial solution to block the exploitation of the SQL Injection vulnerability without fully removing the underlying code flaw. This is a classic example of a workaround, providing immediate protection while a permanent fix is pending.
Why the other options are wrong
- A. Full remediation would involve fixing the underlying code flaw permanently, which isn't happening immediately.
- C. A false positive implies the vulnerability doesn't exist, which contradicts the report and proposed actions.
- D. Risk acceptance would mean doing nothing and accepting the risk, which is not what is being proposed.
Workaround (Vulnerability Management)
A workaround in vulnerability management refers to a temporary or partial measure implemented to reduce the risk of a vulnerability being exploited when a full fix is not immediately possible.
- Does not fully eliminate the vulnerability but mitigates its impact or exploitability.
- Often involves configuration changes, input validation, or compensating controls.
- Should be followed by full remediation as soon as feasible.
Memory trick: Fix IT: Remediate, Workaround, Accept, Reject.