Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard

A security analyst is conducting a post-incident review after a successful ransomware attack. The review reveals that several critical servers were not included in the regular patching schedule, and their operating systems were severely outdated. Furthermore, there was no comprehensive inventory of all IT assets, making it difficult to quickly identify affected systems and their owners during the incident. Which security best practice, if properly implemented, could have significantly mitigated the impact of this incident?

  1. ASecurity Reporting
  2. BAsset Management
  3. CSecurity Awareness Training
  4. DThreat Intelligence
Show answer & explanation

Correct answer: B. Asset Management

The lack of patching and a comprehensive inventory directly points to deficiencies in asset management. Proper asset management includes tracking assets, their configuration, patch status, and ownership, which would have addressed the issues described.

Why the other options are wrong

  • A. Security reporting communicates status, but doesn't prevent or mitigate the root cause of unpatched systems or missing inventory.
  • C. Security awareness training addresses human-centric vulnerabilities, not directly the management of IT assets and patching schedules.
  • D. Threat intelligence provides information about threats but doesn't directly manage internal assets or their patching.

Asset Management (Security)

The systematic process of identifying, tracking, categorizing, and maintaining all organizational assets, including hardware, software, and data, to ensure their security.

  • Crucial for vulnerability management and incident response.
  • Includes maintaining inventory, configurations, and patch levels.
  • Helps understand the scope and impact of security incidents.

Memory trick: Managing assets is like knowing your tools, keeping them sharp and following the rules.

More Security Concepts questions