Question 1 of 30
Consider a scenario where a financial services firm has identified a critical vulnerability (CVSS score of 9.8) in a core banking application that is essential for daily transactions. The vendor has released a patch, but applying it requires a significant system reboot, which could disrupt trading operations for several hours. The IT security team is debating the best course of action to manage this vulnerability. Which of the following approaches best aligns with professional cybersecurity best practices and ethical considerations for managing such a critical vulnerability?
Conduct a thorough risk assessment to understand the exploitability of the vulnerability in the firm's specific environment, evaluate the criticality of the affected system to business operations, and plan the patch deployment during a scheduled low-activity maintenance window, followed by rigorous testing and validation.
Immediately deploy the patch to the core banking application as soon as it is released, accepting the risk of potential operational disruption to ensure the vulnerability is addressed without delay.
Postpone the patching of the core banking application indefinitely until a less disruptive patching method becomes available from the vendor, citing the high risk of operational impact.
Only apply the patch if there is public evidence of active exploitation of this specific vulnerability against similar financial institutions, otherwise, monitor the situation.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free