Hard1 markMultiple Choice
CPA · Question 42 · Area II: Security
An organization discovers a vulnerability in their web server software. The vendor has released a patch, but the organization cannot apply it immediately due to compatibility issues with a legacy application. What is the BEST temporary course of action?
An organization discovers a vulnerability in their web server software. The vendor has released a patch, but the organization cannot apply it immediately due to compatibility issues with a legacy application. What is the BEST temporary course of action?
Answer options:
A.
Accept the risk and do nothing.
B.
Take the server offline.
C.
Implement a compensating control, such as a Web Application Firewall (WAF) rule to block exploits targeting that vulnerability.
D.
Rewrite the legacy application immediately.
How to approach this question
Look for the 'Compensating Control' concept.
Full Answer
C.Implement a compensating control, such as a Web Application Firewall (WAF) rule to block exploits targeting that vulnerability.✓ Correct
C
When a patch cannot be applied immediately, a compensating control is required to mitigate the risk. A Web Application Firewall (WAF) can often be configured to block the specific traffic patterns associated with the exploit (virtual patching).
Common mistakes
Choosing extreme options like 'Shutdown' or 'Do nothing'.
Practice the full CPA ISC Practice Exam 3
82 questions · hints · full answers · grading
More questions from this exam
Q01A CPA is advising a client who is migrating their legacy on-premise ERP system to a cloud-based s...MediumQ02During a review of a client's cloud governance structure, an auditor notes that the client uses a...MediumQ03An auditor is evaluating the 'Processing Integrity' principle for a financial institution's loan ...HardQ04A company uses a batch processing system to update inventory records overnight. The 'Grandfather-...HardQ05During a walkthrough of the change management process, an auditor observes that the 'Developer' r...Medium
Expert