Câu 55: 312-39V2: Certified SOC Analyst (CSA) v2
During a routine security audit, analysts discover that several of the organization's web servers are still using a vulnerable third-party library flagged for a zero-day exploit. This vulnerability was identified in a previous audit, and patches were initially deployed to mitigate the risk. However, due to reported ap…
Nội dung câu hỏi
During a routine security audit, analysts discover that several of the organization's web servers are still using a vulnerable third-party library flagged for a zero-day exploit. This vulnerability was identified in a previous audit, and patches were initially deployed to mitigate the risk. However, due to reported application instability and compatibility issues, the application team rolled back the patches, leaving the systems exposed. Despite the known risk, the vulnerability remains unaddressed, and no alternative mitigations have been put in place. Given the state of the web servers and their reliance on outdated, vulnerable software, how should the security team classify this risk in the context of web application security?
Các lựa chọn
Đáp án được giữ gọn theo nhãn A, B, C, D trong phần bình chọn tương tác.
- A. Vulnerable and Outdated Components — đáp án hiện tại
- B. Software and Data Integrity Failures
- C. Security Logging and Monitoring Failures
- D. Insecure Design
Cộng đồng
0 bình luận công khai. Tên thành viên được ẩn một phần.