Cisco CyberOps Associate (CBROPS) 200-201Vulnerability ManagementMedium
A security analyst is reviewing a vulnerability scan report for a critical database server. The report indicates a 'High' severity vulnerability related to an unpatched operating system. The analyst confirms the OS version is indeed outdated. However, the report also lists a 'Medium' severity vulnerability for an open port 3389 (RDP) but states that the service is configured to only allow connections from an internal jump host and requires multi-factor authentication (MFA). Which of the following is the MOST appropriate next step for the RDP vulnerability?
- AAccept the risk of the open port due to existing compensating controls.
- BImmediately close port 3389 on the database server.
- CRe-scan the server with different credentials to verify the finding.
- DEscalate the finding as a critical vulnerability due to RDP exposure.
Show answer & explanationAnswer & explanation
Correct answer: A. Accept the risk of the open port due to existing compensating controls.
Given the compensating controls (restricted source IP and MFA), the risk associated with the open RDP port is significantly mitigated. Accepting the risk, documenting the controls, and monitoring them is often the most appropriate action rather than closing a necessary port.
Why the other options are wrong
- B. Closing the port might disrupt legitimate access through the jump host, and the existing controls already mitigate the risk.
- C. Re-scanning won't change the fact that the port is open; the issue is about the risk context, not the port's state.
- D. Escalating to critical ignores the mitigating factors; the actual risk is lower than a standard RDP exposure.
Compensating Controls
Security measures that reduce the risk of a vulnerability when it is not feasible or desirable to eliminate the vulnerability itself.
- Mitigate risk, don't remove the vulnerability.
- Must be documented and regularly reviewed.
- Often used for legacy systems or specific operational needs.
Memory trick: Compensating controls are like a 'safety net' for unavoidable risks.