Question 1 of 30
A financial institution is conducting a vulnerability assessment on its network infrastructure. During the assessment, they identify a critical vulnerability in their web application that could allow an attacker to execute arbitrary code. The organization has a policy that mandates all critical vulnerabilities must be remediated within 30 days. However, due to resource constraints, the remediation team estimates that it will take 45 days to fully address the vulnerability. In this context, what is the most appropriate course of action for the organization to take in order to comply with their vulnerability management policy while ensuring the security of their systems?
Implement a temporary workaround to mitigate the risk while planning for a full remediation within the stipulated timeframe.
Accept the risk and document the decision to delay remediation beyond the policy requirement.
Immediately disclose the vulnerability to the public to ensure transparency and seek community assistance.
Increase the resources allocated to the remediation team to meet the 30-day deadline.

Preparing for CISCO 200-201 Understanding Cisco Cybersecurity Operations Fundamentals (CBROPS)? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free