Question 1 of 30
Implementation of a critical security patch for a newly discovered zero-day vulnerability is pending, but the patch has not yet undergone full organizational testing. The vulnerability is being actively exploited in the wild, posing an immediate and significant risk to sensitive customer data. Which of the following actions represents the most prudent and compliant approach to managing this situation?
Deploy a temporary technical control, such as an intrusion prevention system signature or a network access control list, to block known exploit patterns, while simultaneously initiating the formal administrative process for expedited testing and deployment of the permanent patch.
Immediately deploy the un-tested permanent patch to all affected systems to eliminate the vulnerability as quickly as possible, accepting the risk of potential system instability.
Rely solely on existing security controls, assuming they will be sufficient to prevent exploitation of this new vulnerability until the patch is fully tested and deployed through the standard change management process.
Inform senior management of the risk and await their explicit directive on how to proceed, deferring any action until a decision is made at the highest level.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free