ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 178 - CS0-003 discussion

Report
Export

During an internal code review, software called 'ACE' was discovered to have a vulnerability that allows the execution of arbitrary code. The vulnerability is in a legacy, third-party vendor resource that is used by the ACE software. ACE is used worldwide and is essential for many businesses in this industry. Developers informed the Chief Information Security Officer that removal of the vulnerability will take time. Which of the following is the first action to take?

A.
Look for potential loCs in the company.
Answers
A.
Look for potential loCs in the company.
B.
Inform customers of the vulnerability.
Answers
B.
Inform customers of the vulnerability.
C.
Remove the affected vendor resource from the ACE software.
Answers
C.
Remove the affected vendor resource from the ACE software.
D.
Develop a compensating control until the issue can be fixed permanently.
Answers
D.
Develop a compensating control until the issue can be fixed permanently.
Suggested answer: D

Explanation:

A compensating control is an alternative measure that provides a similar level of protection as the original control, but is used when the original control is not feasible or cost-effective. In this case, the CISO should develop a compensating control to mitigate the risk of the vulnerability in the ACE software, such as implementing additional monitoring, firewall rules, or encryption, until the issue can be fixed permanently by the developers.

Reference: CompTIA CySA+ Study Guide: Exam CS0-003, 3rd Edition, Chapter 5, page 197; CompTIA CySA+ CS0-003 Certification Study Guide, Chapter 5, page 205.


asked 02/10/2024
Raza Todorovac
44 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first