ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 345 - CS0-003 discussion

Report
Export

A company patches its servers using automation software. Remote SSH or RDP connections are allowed to the servers only from the service account used by the automation software. All servers are in an internal subnet without direct access to or from the internet. An analyst reviews the following vulnerability summary:

Which of the following vulnerability IDs should the analyst address first?

A.

1

Answers
A.

1

B.

2

Answers
B.

2

C.

3

Answers
C.

3

D.

4

Answers
D.

4

Suggested answer: B

Explanation:

The vulnerability with the highest CVSS score and an active exploit is Microsoft CVE-2021-34527 (PrintNightmare). Although only present on two instances, its high severity (8.4) and exploitable nature make it a priority. PrintNightmare is a well-known remote code execution vulnerability, which can be a critical risk. According to CompTIA CySA+ and vulnerability management practices, prioritizing based on severity and exploitability is essential, even over the number of instances. Other vulnerabilities listed are less severe or lack active exploitation.

asked 17/10/2024
Swen Evers
39 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first