Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy

A company has identified a critical vulnerability in a third-party library used by several of its internal applications. The vendor has released a patch, but applying it immediately would require significant downtime and retesting, which cannot be done until the next maintenance window in two weeks. To mitigate the risk in the interim, the security team decides to implement a temporary measure that reduces the likelihood of exploitation. What is this temporary risk reduction measure called?

  1. AWorkaround
  2. BAcceptance
  3. CRemediation
  4. DTransfer
Show answer & explanation

Correct answer: A. Workaround

A workaround is a temporary solution or configuration change that reduces the risk of a vulnerability being exploited until a permanent fix (remediation) can be applied. It does not eliminate the vulnerability but lessens its impact or likelihood.

Why the other options are wrong

  • B. Acceptance means acknowledging the risk and taking no action, which is contrary to implementing a temporary measure.
  • C. Remediation is the permanent fix, like applying the patch, which is not immediately feasible in this scenario.
  • D. Transferring risk involves shifting it to another party, like buying insurance, which is not what's described here.

Workaround (Vulnerability Management)

A temporary measure or configuration change implemented to reduce the risk associated with a vulnerability until a permanent fix can be applied.

  • Temporary solution.
  • Reduces likelihood or impact, but doesn't eliminate the vulnerability.
  • Often used when full remediation requires downtime or extended effort.

Memory trick: Fix, Bypass, Ignore, Share.

More Vulnerability Management questions