Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementMedium

A security analyst is reviewing a vulnerability report for a critical web application. The report highlights a SQL Injection vulnerability that could allow an attacker to extract sensitive data from the database. The development team states they cannot immediately patch the vulnerability due to a complex release cycle. To address the immediate risk, they propose implementing input validation and parameterized queries in the application layer. What type of vulnerability management action is this?

  1. AFull Remediation
  2. BWorkaround
  3. CFalse Positive
  4. DRisk Acceptance
Show answer & explanation

Correct answer: B. Workaround

Implementing input validation and parameterized queries acts as a temporary or partial solution to block the exploitation of the SQL Injection vulnerability without fully removing the underlying code flaw. This is a classic example of a workaround, providing immediate protection while a permanent fix is pending.

Why the other options are wrong

  • A. Full remediation would involve fixing the underlying code flaw permanently, which isn't happening immediately.
  • C. A false positive implies the vulnerability doesn't exist, which contradicts the report and proposed actions.
  • D. Risk acceptance would mean doing nothing and accepting the risk, which is not what is being proposed.

Workaround (Vulnerability Management)

A workaround in vulnerability management refers to a temporary or partial measure implemented to reduce the risk of a vulnerability being exploited when a full fix is not immediately possible.

  • Does not fully eliminate the vulnerability but mitigates its impact or exploitability.
  • Often involves configuration changes, input validation, or compensating controls.
  • Should be followed by full remediation as soon as feasible.

Memory trick: Fix IT: Remediate, Workaround, Accept, Reject.

More Vulnerability Management questions