A security analyst is investigating a potential compromise. Logs show that an attacker exploited a known vulnerability in a web server's content management system (CMS) that was identified in a scan two weeks prior. The vulnerability was triaged with a 'Medium' priority and remediation was scheduled for the next month. Which stage of the vulnerability management lifecycle failed in this scenario?
- ARemediation
- BIdentification
- CMonitoring
- DAssessment and Prioritization
Show answer & explanationAnswer & explanation
Correct answer: D. Assessment and Prioritization
The vulnerability was 'identified' (A) by the scan. The 'Remediation' (C) stage involves applying the fix, which was scheduled but not yet executed. 'Monitoring' (D) implies continuous oversight, which would have ideally prevented the exploit, but the core issue was the initial decision-making. The failure lies in the 'Assessment and Prioritization' (B) stage, where the 'Medium' priority assigned to a known, exploitable vulnerability on a web server allowed a significant delay in remediation, ultimately leading to a compromise. The risk was underestimated.
Why the other options are wrong
- A. Remediation was scheduled but not yet completed; the failure was in the scheduling decision, not the physical act of remediation itself.
- B. Identification was successful as the vulnerability was found by the scan.
- C. Monitoring would ideally catch the exploit, but the root cause of the compromise was the insufficient priority assigned to the vulnerability.
Vulnerability Prioritization Failure
Occurs when the assigned severity or priority of a vulnerability does not accurately reflect its true risk to the organization, leading to delayed or inadequate remediation and potential exploitation.
- Can result from underestimating exploitability or impact.
- Often leads to critical vulnerabilities being addressed too late.
- Requires a holistic view of the vulnerability, asset, and threat landscape.
Memory trick: Identify, Assess, Remediate, Monitor: The continuous cycle of security.