ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 407 - CAS-004 discussion

Report
Export

A hospital has fallen behind with patching known vulnerabilities due to concerns that patches may cause disruptions in the availability of data and impact patient care. The hospital does not have a tracking solution in place to audit whether systems have been updated or to track the length of time between notification of the weakness and patch completion Since tracking is not in place the hospital lacks accountability with regard to who is responsible for these activities and the timeline of patching efforts. Which of the following should the hospital do first to mitigate this risk?

A.
Complete a vulnerability analysis
Answers
A.
Complete a vulnerability analysis
B.
Obtain guidance from the health ISAC
Answers
B.
Obtain guidance from the health ISAC
C.
Purchase a ticketing system for auditing efforts
Answers
C.
Purchase a ticketing system for auditing efforts
D.
Ensure CVEs are current
Answers
D.
Ensure CVEs are current
E.
Train administrators on why patching is important
Answers
E.
Train administrators on why patching is important
Suggested answer: A

Explanation:

The first step in mitigating the risk associated with delayed patching is to conduct a vulnerability analysis. This process involves identifying, categorizing, and assessing the vulnerabilities within the hospital's IT infrastructure. By understanding the specific vulnerabilities and their potential impact on patient care and data availability, the hospital can prioritize patching efforts effectively and develop a strategy that minimizes disruptions while ensuring critical systems remain secure.

asked 02/10/2024
Miroslav Vukic
37 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first