QuestionQ67

Security Engineering

An organization’s load balancers have reached EOL and are planned for replacement. The organization has identified a new, critical vulnerability that affects an unused load-balancer function. Which of the following are the best ways to address the organization’s risk?

Choose two
  • A Request a risk acceptance for the vulnerability indefinitely.
  • B Request a risk acceptance for the vulnerability for 90 days.
  • C Exclude the devices from vulnerability scans.
  • D Do not allow any network traffic to or from the hardware.
  • E Disable the vulnerable service.
  • F Immediately decommission the hardware.
Explanation

Disabling an unused vulnerable service removes the vulnerable attack surface while preserving the load balancers’ required functions. A documented, time-limited risk acceptance provides controlled temporary treatment of any residual risk while the scheduled replacement is completed; an indefinite acceptance does not appropriately govern a critical vulnerability.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!