QuestionQ45

Incident Response and Management

An incident response team discovers a malicious uniform resource locator (URL) associated with a required business process and carries out the following actions:

  • Access to the URL has been limited to only the required users by using firewall rules and Cloud Security Group rules.
  • Extra monitoring has been enabled for traffic related to that site and the permitted users.
  • All application servers requiring access to that site have been patched with the latest security and software updates.
  • Application owners have been informed of the severity and the need to remediate the reported issue.

Which of the following best characterizes the overall mitigation being performed by the security team?

Explanation

Compensating controls are alternative safeguards that reduce risk when an underlying issue cannot yet be fully removed or remediated. Restricting URL access, monitoring the permitted traffic, and hardening affected servers limit exposure while application owners work on remediation.

Community Discussion

No comments yet. Be the first to start the discussion!