Cisco CCNP Security Core (SCOR) 350-701Security ConceptsHard

A company is performing a detailed analysis of potential vulnerabilities in their web application. They are specifically focusing on identifying weaknesses that could be exploited by malicious actors, such as SQL injection flaws, cross-site scripting (XSS), and insecure direct object references (IDOR). This activity is a core part of which process?

  1. ASecurity Reporting
  2. BSecurity Operations
  3. CRisk Management
  4. DSecurity Audits
Show answer & explanation

Correct answer: C. Risk Management

Identifying specific vulnerabilities like SQL injection, XSS, and IDOR, with the intent to understand how they could be exploited, is a crucial step in the risk assessment phase of risk management. Risk management involves identifying, assessing, and mitigating risks to an organization's assets.

Why the other options are wrong

  • A. Security reporting is communicating findings, not the process of finding vulnerabilities.
  • B. Security operations are day-to-day activities; while they might *detect* exploitation, *identifying* potential weaknesses is a proactive risk management task.
  • D. Security audits verify compliance and control effectiveness, but the scenario focuses on *identifying* weaknesses for *potential exploitation*.

Risk Management

The systematic process of identifying, assessing, and treating risks to an organization's assets, ensuring that security controls are proportionate to the level of risk.

  • Involves risk identification, analysis, evaluation, and treatment.
  • Aims to reduce risks to an acceptable level.
  • Often uses vulnerability assessments and threat modeling.

Memory trick: Risk Management is 'RISK'ing 'MANAGE'ment 'ACTIONS'.

More Security Concepts questions