- Get link
- X
- Other Apps
CYB 205 Infrastructure Administration
Q: The common vulnerabilities and exposures (CVE) data and your own vulnerability assessments indicate that many of your end-user systems do not include recent security patches released by the software vendors. You decide to bring these systems up to date by applying these patches. This is an example of which of the following?
A: Remediating or mitigating a risk
Explanation: Fixing or applying patches to eliminate a vulnerability is the definition of remediating, mitigating, fixing, or repairing a vulnerability. The risk mitigation strategy attempts to lower the probability and/or impact of a risk occurring.Answer D is incorrect. Transferring a risk involves paying someone else to take on the work of repairs, reimbursements, or replacement of damaged systems if the risk event occurs.Answer C is incorrect. Avoiding a risk involves changing a business process so that the risk no longer applies.Answer B is incorrect. Accepting a risk involves accepting the identified risk and not taking any other action to reduce the risk.
- Get link
- X
- Other Apps
Comments
Post a Comment