Question 1 of 30
Risk assessment procedures indicate that a newly discovered critical vulnerability (CVSS score of 9.8) has been identified in a widely used third-party application deployed across multiple departments. However, the IT operations team has expressed significant concerns about the potential for widespread service disruption if the application is patched immediately, citing a history of compatibility issues with recent updates. The security team is pushing for immediate remediation due to the high severity of the vulnerability. What is the most appropriate course of action to manage this situation effectively?
Conduct a targeted risk assessment to understand the specific impact of the vulnerability on critical business functions and systems, explore temporary mitigation strategies, and develop a phased remediation plan that prioritizes systems based on their criticality and exploitability, while coordinating closely with IT operations to minimize disruption.
Immediately deploy the patch to all systems running the affected application, regardless of potential operational impact, to address the critical vulnerability as quickly as possible.
Prioritize patching based on the age of the vulnerability, addressing older, less critical vulnerabilities first to avoid disrupting the deployment of newer, potentially more impactful patches.
Defer all patching for this application until a more stable version is released by the vendor, accepting the inherent risk associated with the critical vulnerability in the interim.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free