Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Security OperationsMedium
A SOC analyst is performing a security assessment and identifies an unpatched web server with a known critical vulnerability that could allow remote code execution. The analyst creates a ticket for the IT team to apply the patch immediately. This action is part of which continuous security process?
- AThreat Hunting
- BVulnerability Management
- CSecurity Information and Event Management (SIEM)
- DIncident Response
Show answer & explanationAnswer & explanation
Correct answer: B. Vulnerability Management
Vulnerability management is the continuous process of identifying, assessing, prioritizing, and remediating security weaknesses (vulnerabilities) in systems and applications. Identifying an unpatched server and initiating a patch falls directly into this process.
Why the other options are wrong
- A. Threat hunting is proactive, but focuses on finding existing, undetected threats, not unpatched vulnerabilities.
- C. SIEM is for collecting and analyzing logs for real-time threat detection, not proactive vulnerability identification.
- D. Incident Response is reactive, dealing with active security breaches, not proactive patching.
Vulnerability Management
Vulnerability Management is the continuous, cyclical process of identifying, assessing, prioritizing, and remediating security weaknesses (vulnerabilities) in an organization's systems and applications to reduce their attack surface.
- Proactive security process.
- Involves scanning, assessment, and remediation.
- Aims to reduce attack surface.
Memory trick: Prevent, Detect, Respond, Recover.