SSCP Systems Security Certified PractitionerRisk Identification, Monitoring, and AnalysisHard
A security analyst is investigating a potential data breach. They discover that sensitive customer data was exfiltrated from a web server due to an unpatched vulnerability in the web application. The organization had identified this vulnerability during a previous scan but had not yet applied the patch. What is the primary contributor to this data breach from a risk management perspective?
- AFailure to effectively manage vulnerabilities.
- BLack of threat intelligence sharing.
- CAbsence of a robust incident response plan.
- DInsufficient security awareness training.
Show answer & explanationAnswer & explanation
Correct answer: A. Failure to effectively manage vulnerabilities.
The core issue described is that a known vulnerability (identified in a scan) was not patched, leading to its exploitation. This directly points to a breakdown in the organization's vulnerability management process.
Why the other options are wrong
- B. While important, threat intelligence sharing wouldn't directly prevent the exploitation of an already known and identified, but unpatched, vulnerability.
- C. An incident response plan is for reacting to a breach, not preventing it by addressing known vulnerabilities beforehand.
- D. Security awareness training addresses human-centric risks (like phishing), not directly unpatched server vulnerabilities.
Vulnerability Management
The cyclical process of identifying, assessing, prioritizing, remediating, and verifying vulnerabilities in an organization's systems and applications.
- Crucial for proactive security.
- Involves regular scanning, patching, and configuration management.
- Aims to reduce the attack surface.
Memory trick: The 'known but not fixed' problem is key.