Palo Alto Networks Certified Cybersecurity Entry-level Technician (PCCET)Network SecurityMedium
A network security team is investigating an incident where an internal server was compromised. Forensic analysis shows that the attacker gained initial access by exploiting a known vulnerability in an outdated operating system service. Which security principle, if consistently applied, would have best prevented this initial compromise?
- APrinciple of Least Privilege
- BStrong Password Policy
- CNetwork Segmentation
- DRegular Patch Management
Show answer & explanationAnswer & explanation
Correct answer: D. Regular Patch Management
The compromise was due to a 'known vulnerability in an outdated operating system service'. Regular patch management directly addresses this by ensuring systems are updated with the latest security fixes, thereby closing known vulnerabilities.
Why the other options are wrong
- A. Principle of Least Privilege limits user/process access, which is crucial for containing damage but wouldn't prevent the initial exploitation of an unpatched vulnerability.
- B. Strong password policies prevent brute-force or dictionary attacks on credentials but do not protect against exploits targeting software vulnerabilities.
- C. Network segmentation limits lateral movement after a breach but doesn't prevent the initial exploitation of an externally accessible, unpatched vulnerability.
Patch Management
The process of regularly acquiring, testing, and applying code changes (patches) to software and operating systems to fix bugs, improve performance, and, crucially, address security vulnerabilities.
- Crucial for maintaining a strong security posture.
- Reduces the attack surface by eliminating known exploits.
- Requires a systematic approach to ensure all systems are updated.
Memory trick: Fixing holes before they're exploited is like patching a leaky roof.