Cisco Certified Support Technician (CCST) CybersecurityEndpoint SecurityMedium

A security analyst is investigating a compromised workstation. The investigation reveals that the attacker gained initial access by exploiting a vulnerability in an outdated web browser. The attacker then installed a backdoor. To prevent similar incidents, the organization needs to implement a continuous process to ensure all software, including operating systems and applications, are kept up-to-date with the latest security fixes. Which endpoint security best practice would address this need?

  1. AVulnerability Scanning
  2. BPatch Management
  3. CApplication Whitelisting
  4. DSecurity Awareness Training
Show answer & explanation

Correct answer: B. Patch Management

Patch Management is the systematic process of identifying, acquiring, testing, and applying updates (patches) to software and operating systems. This practice is essential for closing known security vulnerabilities that attackers often exploit, like the outdated web browser in the scenario.

Why the other options are wrong

  • A. Vulnerability Scanning identifies weaknesses, but Patch Management applies the fixes.
  • C. Application Whitelisting controls what software can run, but doesn't ensure existing software is updated and secure.
  • D. Security Awareness Training educates users, but doesn't directly manage software updates.

Patch Management

The systematic process of identifying, acquiring, testing, and applying updates (patches) to software, firmware, and operating systems to fix bugs, improve functionality, and resolve security vulnerabilities.

  • Crucial for reducing the attack surface by closing known security gaps.
  • Requires a structured approach to avoid system instability.
  • Includes regular scanning for missing patches and scheduled deployment.

Memory trick: Patch management is like regularly mending holes in your digital fence before intruders find them.

More Endpoint Security questions