Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementEasy
A security analyst is reviewing logs after a recent vulnerability scan of several web servers. The scan report indicates multiple instances of 'CVE-2023-XXXX' related to outdated Apache HTTP Server versions. The analyst needs to determine the immediate next step to mitigate this specific vulnerability. Which action should the analyst prioritize?
- AIsolate the servers from the network and re-image them.
- BApply the latest security patches to the affected Apache servers.
- CPerform a penetration test to confirm exploitability.
- DUpdate the vulnerability scanner's signature database.
Show answer & explanationAnswer & explanation
Correct answer: B. Apply the latest security patches to the affected Apache servers.
Applying security patches is the most direct and immediate way to mitigate a known vulnerability caused by outdated software versions. Penetration testing confirms exploitability but doesn't fix the issue, updating the scanner is for future scans, and re-imaging is an extreme measure for this scenario.
Why the other options are wrong
- A. Re-imaging is an overly drastic and time-consuming measure for a known software vulnerability.
- C. Penetration testing confirms exploitability but does not resolve the vulnerability itself.
- D. Updating the scanner helps identify new vulnerabilities but won't fix existing ones.
Patch Management
The process of acquiring, testing, and applying code changes (patches) to software and systems to fix bugs, enhance features, and, most importantly, address security vulnerabilities.
- Crucial for maintaining system security.
- Involves regular monitoring for new patches.
- Requires testing before widespread deployment.
Memory trick: Patching up holes keeps systems whole.