SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium

During a post-incident review, a security team determines that a recent breach could have been prevented if security patches had been applied to a critical server two months prior. The vulnerability was publicly disclosed, and a patch was available. This situation highlights a failure in which aspect of the security program?

  1. AThreat intelligence gathering
  2. BSecurity incident response
  3. CVulnerability management
  4. DSecurity awareness training
Show answer & explanation

Correct answer: C. Vulnerability management

The scenario explicitly states that a publicly disclosed vulnerability with an available patch was not applied, leading to a breach. This is a direct failure in the organization's vulnerability management process, which includes identifying, assessing, and remediating vulnerabilities in a timely manner.

Why the other options are wrong

  • A. Threat intelligence gathering might inform vulnerability management, but the core failure here is in applying known patches.
  • B. Incident response deals with what happens after a breach, while the question focuses on prevention that failed before the breach.
  • D. Security awareness training is for user behavior, not for patching servers.

Vulnerability Management

The cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities in systems and applications.

  • Includes scanning, assessment, prioritization, patching, and verification.
  • A continuous process, not a one-time activity.
  • Crucial for reducing an organization's attack surface.

Memory trick: Protect, Detect, Respond, Recover; but first, manage vulnerabilities.

More Risk Identification, Monitoring, and Analysis questions