Question 1 of 30
Consider a scenario where a cybersecurity team has identified a significant number of vulnerabilities across an organization\'s network, including critical, high, and medium severity issues. Some critical vulnerabilities have publicly known exploits, while others are theoretical but could have a severe impact if exploited. The IT operations team has expressed concerns about the potential for system downtime and disruption if all identified vulnerabilities are patched immediately. How should the cybersecurity team proceed to effectively manage these vulnerabilities?
Conduct a thorough risk assessment to prioritize vulnerabilities based on their severity, exploitability, and impact on critical business functions, then develop a phased patching plan that balances security needs with operational stability.
Immediately patch all identified critical vulnerabilities, regardless of system criticality or potential operational impact, to eliminate all known risks as quickly as possible.
Focus exclusively on patching vulnerabilities that have publicly available exploits, deferring patches for theoretical vulnerabilities until they become actively exploited.
Postpone all patching activities until the IT operations team can guarantee a period of zero system downtime, prioritizing operational continuity over immediate security remediation.

Preparing for CompTIA CySA+ Exam? Now land the interview.

73% of qualified candidates get rejected because of weak resumes. Build an ATS-optimized, recruiter-ready resume in under 5 minutes - free to start.

Build My Resume Free