CompTIA CySA+ (CS0-003)Vulnerability ManagementEasy
A security analyst is reviewing a vulnerability scan report that lists several critical findings on a web server. One finding indicates that the web server software (Apache HTTP Server) is running an outdated version with a known critical vulnerability. The report recommends upgrading Apache to the latest stable version. Which of the following remediation strategies is MOST effective for this type of vulnerability?
- AImplementing a Web Application Firewall (WAF) in front of the server.
- BApplying the vendor-provided patch or upgrading the software.
- CIsolating the web server in a separate network segment.
- DDisabling the vulnerable features of the Apache HTTP Server.
Show answer & explanationAnswer & explanation
Correct answer: B. Applying the vendor-provided patch or upgrading the software.
Applying vendor-provided patches or upgrading software directly addresses the root cause of vulnerabilities stemming from outdated software. This is generally the most effective and direct remediation strategy. Other options might mitigate risk but do not resolve the underlying vulnerability.
Why the other options are wrong
- A. A WAF can help protect against web-based attacks but does not fix the underlying vulnerability in the outdated Apache software itself.
- C. Network segmentation can limit the impact of an exploit but does not remove the vulnerability from the server itself.
- D. Disabling features might reduce the attack surface, but it's often impractical and doesn't resolve the core vulnerability if the feature is essential.
Vulnerability Remediation
The process of eliminating or mitigating a vulnerability to reduce the risk it poses.
- Directly fixes the root cause of the vulnerability.
- Often involves patching, upgrading, or reconfiguring.
- Most effective strategy for known software flaws.
Memory trick: Remediate means to fix the problem, not just cover it up.