QuestionQ17

Cloud Posture Security

A company receives a critical vulnerability finding with a CVSS score of 10 on a workload that has been virtually patched using a WAF. The security team must track the issue appropriately based on the risk to the company environment and in alignment with its risk-management approach.

Which action can the security team take in Cortex Cloud?

  • A Fail builds containing the vulnerability in CI/CD pipelines.
  • B Recast the CVSS score and vulnerability severity.
  • C Tag the vulnerability as “Ignored”.
  • D Ensure the issue is sent to the SOC for analysis.
Explanation

A virtual patch implemented through a WAF is a compensating control that can reduce the vulnerability’s residual risk in the specific environment while the underlying vulnerability remains present. Recasting the CVSS score and severity records that contextual risk assessment in accordance with the organization’s risk-management policy, without removing the finding from tracking.

Community Discussion

No comments yet. Be the first to start the discussion!