ExamGecko
Question list
Search
Search

List of questions

Search

Related questions











Question 308 - PT0-002 discussion

Report
Export

Penetration on an assessment for a client organization, a penetration tester notices numerous outdated software package versions were installed ...s-critical servers. Which of the following would best mitigate this issue?

A.
Implementation of patching and change control programs
Answers
A.
Implementation of patching and change control programs
B.
Revision of client scripts used to perform system updates
Answers
B.
Revision of client scripts used to perform system updates
C.
Remedial training for the client's systems administrators
Answers
C.
Remedial training for the client's systems administrators
D.
Refrainment from patching systems until quality assurance approves
Answers
D.
Refrainment from patching systems until quality assurance approves
Suggested answer: A

Explanation:

The best way to mitigate this issue is to implement patching and change control programs, which are processes that involve applying updates or fixes to software packages to address vulnerabilities, bugs, or performance issues, and managing or documenting the changes made to the software packages to ensure consistency, compatibility, and security. Patching and change control programs can help prevent or reduce the risk of attacks that exploit outdated software package versions, which may contain known or unknown vulnerabilities that can compromise the security or functionality of the systems or servers. Patching and change control programs can be implemented by using tools such as WSUS, which is a tool that can manage and distribute updates for Windows systems and applications1, or Git, which is a tool that can track and control changes to source code or files2. The other options are not valid ways to mitigate this issue. Revision of client scripts used to perform system updates is not a sufficient way to mitigate this issue, as it may not address the root cause of why the software package versions are outdated, such as lack of awareness, resources, or policies.

Remedial training for the client's systems administrators is not a direct way to mitigate this issue, as it may not result in immediate or effective actions to update the software package versions.

Refrainment from patching systems until quality assurance approves is not a way to mitigate this issue, but rather a potential cause or barrier for why the software package versions are outdated.


asked 02/10/2024
Jonathan Marboux
34 questions
User
Your answer:
0 comments
Sorted by

Leave a comment first