SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisMedium
During a post-incident review, a security team determines that a recent breach could have been prevented if security patches had been applied to a critical server two months prior. The vulnerability was publicly disclosed, and a patch was available. This situation highlights a failure in which aspect of the security program?
- AThreat intelligence gathering
- BSecurity incident response
- CVulnerability management
- DSecurity awareness training
Show answer & explanationAnswer & explanation
Correct answer: C. Vulnerability management
The scenario explicitly states that a publicly disclosed vulnerability with an available patch was not applied, leading to a breach. This is a direct failure in the organization's vulnerability management process, which includes identifying, assessing, and remediating vulnerabilities in a timely manner.
Why the other options are wrong
- A. Threat intelligence gathering might inform vulnerability management, but the core failure here is in applying known patches.
- B. Incident response deals with what happens after a breach, while the question focuses on prevention that failed before the breach.
- D. Security awareness training is for user behavior, not for patching servers.
Vulnerability Management
The cyclical practice of identifying, classifying, remediating, and mitigating vulnerabilities in systems and applications.
- Includes scanning, assessment, prioritization, patching, and verification.
- A continuous process, not a one-time activity.
- Crucial for reducing an organization's attack surface.
Memory trick: Protect, Detect, Respond, Recover; but first, manage vulnerabilities.