Question 1 of 30
Process analysis reveals a critical zero-day vulnerability in a third-party software component used extensively across your organization\'s infrastructure, which processes sensitive customer data. The vendor has released an emergency patch, but it has not undergone extensive testing due to the urgency. Your organization is subject to GDPR and PCI-DSS. Which of the following actions represents the most responsible and compliant approach to managing this situation?
Initiate an immediate internal risk assessment to understand the vulnerability's impact, engage with the vendor for patch details, and plan a phased rollout of the patch starting with non-production environments to validate its stability and effectiveness before full deployment, while preparing transparent client communications.
Deploy the emergency patch across all production systems immediately to mitigate the risk of exploitation, as the potential for a breach outweighs the risk of patch-related instability.
Wait for the vendor to release a more thoroughly tested, stable version of the patch, and in the interim, implement temporary network segmentation to isolate affected systems.
Focus solely on patching the identified vulnerability and disregard any potential impact on system performance or client-facing services, assuming the vendor's patch is inherently secure.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free