Question 1 of 30
The assessment process reveals a significant security vulnerability that could expose sensitive customer personally identifiable information (PII). The IT security team has identified a potential fix, but its implementation might temporarily disrupt critical business operations. The legal and compliance department is concerned about potential regulatory penalties under applicable data privacy laws if the vulnerability is exploited before a fix is deployed, or if the fix itself causes data loss. What is the most appropriate course of action?
Conduct a rapid, targeted impact assessment to determine the exact scope of potential data exposure and the criticality of affected systems, then develop and implement a phased remediation plan that prioritizes the most severe risks while minimizing operational disruption, ensuring all actions are documented and reviewed against regulatory requirements.
Immediately deploy the identified fix to eliminate the vulnerability, accepting the risk of temporary operational disruption and potential data loss as a necessary trade-off for immediate security.
Delay any remediation efforts until a comprehensive, long-term security overhaul can be completed, to avoid any short-term operational impact or negative publicity.
Implement a superficial workaround, such as disabling the affected feature temporarily, without fully addressing the underlying vulnerability, to avoid immediate operational disruption and potential data loss.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free