Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementHard

A company policy dictates that all critical servers must be patched within 72 hours of a security patch release. A recent vulnerability scan report shows that several critical servers have not received a widely publicized patch for a severe OS vulnerability, 96 hours after its release. This situation indicates a failure in which aspect of vulnerability management?

  1. ARisk Prioritization
  2. BVulnerability Identification
  3. CPatch Deployment
  4. DVulnerability Assessment
Show answer & explanation

Correct answer: C. Patch Deployment

The problem isn't identifying the vulnerability (it was widely publicized and found by a scan) or prioritizing it (it's critical). The failure is in the execution of applying the patch within the defined timeframe, which falls under patch deployment.

Why the other options are wrong

  • A. Risk prioritization determines which vulnerabilities to address first; a 'severe OS vulnerability' on 'critical servers' would already be high priority.
  • B. Vulnerability identification is about discovering the vulnerability; this was already 'widely publicized'.
  • D. Vulnerability assessment is about analyzing and understanding vulnerabilities, which seems to have happened as it's a known, severe OS vulnerability.

Patch Management Failure

A breakdown in the process of acquiring, testing, and applying software updates (patches) to systems, leading to unpatched vulnerabilities.

  • Can result from poor planning, insufficient resources, or technical issues.
  • Increases exposure to known exploits.
  • Often a compliance issue.

Memory trick: Missing the patch deadline is like a 'broken clock' for security updates.

More Vulnerability Management questions