QuestionQ40

Vulnerability Management

A vulnerability scan identifies the following vulnerabilities in the environment:

Question Image

At the same time, the following security advisory is released:

> “A zero-day vulnerability with a CVSS score of 10 may be affecting your web server. The vendor is working on a patch or workaround.”

Which action should the security analyst take first?

Explanation

The scan produced three confirmed, actionable findings — a storage server application flaw (CVSS 9.0), a firewall web interface left on default credentials (CVSS 8.9), and an RDP weakness on workstations (CVSS 6.5) — all of which have known root causes and available remediation paths, so a risk-based prioritization strategy can begin on them immediately. The web server is not among the scanned findings; it is only the subject of an advisory saying a zero-day 'may be' affecting it, with the vendor still developing a patch or workaround, so the analyst's productive move is to route that advisory to the team that owns the web environment for validation, compensating-control planning, and vendor tracking. Re-running the scan is futile because a newly disclosed zero-day has no detection signature or plugin yet, and the confirmed findings were already reported by the scan just completed. Demanding an immediate shutdown of a production web server on an unverified 'may be affected' notice is a disproportionate, unilateral action that bypasses the system owner and change control; taking an asset offline is an emergency mitigation reserved for confirmed exposure and is a decision for the owning team, not the first step for the analyst. Passive patch monitoring alone leaves the already-confirmed critical vulnerabilities unaddressed.

Learn more

Community Discussion

No comments yet. Be the first to start the discussion!