Question 1 of 29
Quality control measures reveal a significant number of high-severity vulnerabilities across the organization\'s IT infrastructure. A critical business application, responsible for processing sensitive customer data and generating daily financial reports, has been identified with several high-severity vulnerabilities. The IT operations team expresses concern that applying immediate patches to this application could disrupt its availability, potentially halting financial reporting for a day. The security team, however, emphasizes the immediate risk of exploitation. What is the most appropriate course of action?
Conduct a rapid risk assessment to determine the exploitability of the vulnerabilities in the wild, the presence of compensating controls, and the specific business impact of a potential outage versus a potential breach, then prioritize remediation based on this assessment.
Immediately deploy patches to all identified high-severity vulnerabilities across all systems, including the critical business application, to mitigate the risk of exploitation as quickly as possible.
Defer patching the critical business application indefinitely until a major maintenance window can be scheduled, citing the importance of uninterrupted financial reporting.
Initiate automated patching for all high-severity vulnerabilities without further review, assuming that automated processes will handle any potential operational conflicts.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free