Cisco Certified Support Technician (CCST) CybersecurityVulnerability ManagementEasy
A cybersecurity analyst has identified a critical vulnerability in a web application. The vulnerability allows unauthenticated users to bypass login and access sensitive customer data. The development team has acknowledged the issue but states a patch will take at least two weeks to develop and deploy. Which of the following is the BEST immediate action to take to protect the data while awaiting the permanent fix?
- ADisable the web application entirely until the patch is ready.
- BInform all customers about the data exposure risk and advise them to change their passwords.
- CImplement a web application firewall (WAF) rule to block requests exploiting the vulnerability.
- DPerform a penetration test to confirm the vulnerability's exploitability.
Show answer & explanationAnswer & explanation
Correct answer: C. Implement a web application firewall (WAF) rule to block requests exploiting the vulnerability.
Implementing a web application firewall (WAF) rule provides an immediate, temporary layer of protection by blocking known attack patterns, thus mitigating the risk until a permanent patch is deployed. This is a common and effective temporary control.
Why the other options are wrong
- A. Disabling the application can cause significant business disruption and may not always be feasible.
- B. While transparency is important, informing customers about data exposure without first mitigating the threat could cause panic and reputational damage. This is a reactive, not proactive, immediate protection.
- D. A penetration test confirms exploitability but does not provide immediate protection against the identified vulnerability; the goal is already to protect the data, not to re-confirm the problem.
Temporary Mitigation
A temporary measure taken to reduce the immediate risk of an identified vulnerability while a permanent solution is being developed or implemented.
- Provides immediate protection.
- Not a permanent fix.
- Often involves configuration changes or security device rules.
Memory trick: When a vulnerability hits hard, shield it fast, buy time for the permanent fix, and keep business moving.