Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementHard
A company policy dictates that all critical servers must be patched within 72 hours of a security patch release. A recent vulnerability scan report shows that several critical servers have not received a widely publicized patch for a severe OS vulnerability, 96 hours after its release. This situation indicates a failure in which aspect of vulnerability management?
- ARisk Prioritization
- BVulnerability Identification
- CPatch Deployment
- DVulnerability Assessment
Show answer & explanationAnswer & explanation
Correct answer: C. Patch Deployment
The problem isn't identifying the vulnerability (it was widely publicized and found by a scan) or prioritizing it (it's critical). The failure is in the execution of applying the patch within the defined timeframe, which falls under patch deployment.
Why the other options are wrong
- A. Risk prioritization determines which vulnerabilities to address first; a 'severe OS vulnerability' on 'critical servers' would already be high priority.
- B. Vulnerability identification is about discovering the vulnerability; this was already 'widely publicized'.
- D. Vulnerability assessment is about analyzing and understanding vulnerabilities, which seems to have happened as it's a known, severe OS vulnerability.
Patch Management Failure
A breakdown in the process of acquiring, testing, and applying software updates (patches) to systems, leading to unpatched vulnerabilities.
- Can result from poor planning, insufficient resources, or technical issues.
- Increases exposure to known exploits.
- Often a compliance issue.
Memory trick: Missing the patch deadline is like a 'broken clock' for security updates.