Question 1 of 30
Quality control measures reveal a significant number of critical vulnerabilities across various internal and external systems. The CISO has mandated immediate patching of all identified critical vulnerabilities, emphasizing a \"no exceptions\" policy to mitigate potential breaches. However, the IT operations team has raised concerns that an immediate, blanket patching of all critical vulnerabilities could lead to substantial downtime for several key business applications, potentially impacting revenue streams and customer service. As the lead security analyst, you need to advise the CISO on the most appropriate course of action. Which of the following approaches best balances security imperatives with operational realities?
Conduct a detailed risk assessment for each critical vulnerability, prioritizing remediation efforts based on a combination of vulnerability severity, exploitability, and the potential business impact of patching or not patching. Develop a phased remediation plan that addresses the highest risks first, with clear communication and rollback strategies for critical systems.
Immediately deploy patches for all identified critical vulnerabilities across all systems, overriding any operational concerns raised by the IT operations team to strictly adhere to the CISO's directive.
Defer patching of all critical vulnerabilities until the next scheduled maintenance window, citing the potential for business disruption, and focus only on monitoring for active exploitation.
Prioritize patching only for critical vulnerabilities found on systems directly accessible from the public internet, as these represent the most immediate external threat.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free