ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 233 - CS0-003 discussion

Report
Export

A recent vulnerability scan resulted in an abnormally large number of critical and high findings that require patching. The SLA requires that the findings be remediated within a specific amount of time. Which of the following is the best approach to ensure all vulnerabilities are patched in accordance with the SLA?

A.
Integrate an IT service delivery ticketing system to track remediation and closure.
Answers
A.
Integrate an IT service delivery ticketing system to track remediation and closure.
B.
Create a compensating control item until the system can be fully patched.
Answers
B.
Create a compensating control item until the system can be fully patched.
C.
Accept the risk and decommission current assets as end of life.
Answers
C.
Accept the risk and decommission current assets as end of life.
D.
Request an exception and manually patch each system.
Answers
D.
Request an exception and manually patch each system.
Suggested answer: A

Explanation:

Integrating an IT service delivery ticketing system to track remediation and closure is the best approach to ensure all vulnerabilities are patched in accordance with the SLA. A ticketing system is a software tool that helps manage, organize, and track the tasks and workflows related to IT service delivery, such as incident management, problem management, change management, and vulnerability management. A ticketing system can help the security team to prioritize, assign, monitor, and document the remediation of the vulnerabilities, and to ensure that they are completed within the specified time frame and quality standards. A ticketing system can also help the security team to communicate and collaborate with other teams, such as the IT operations team, the development team, and the business stakeholders, and to report on the status and progress of the remediation efforts12. Creating a compensating control item, accepting the risk, and requesting an exception are not the best approaches to ensure all vulnerabilities are patched in accordance with the SLA, as they do not address the root cause of the problem, which is the large number of critical and high findings that require patching. These approaches may also introduce more risks or challenges for the security team, such as compliance issues, resource constraints, or business impacts3 .

Reference: What is a Ticketing System? | Freshservice ITSM Glossary, Vulnerability Management Best Practices, Compensating Controls: An Impermanent Solution to an IT ... - Tripwire, [Risk Acceptance in Information Security - Infosec Resources], [Exception Management - ISACA]

asked 02/10/2024
Mellisa Stroman
38 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first