exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 402 discussion

Actual exam question from CompTIA's CAS-004
Question #: 402
Topic #: 1
[All CAS-004 Questions]

A hospital has fallen behind with patching known vulnerabilities due to concerns that patches may cause disruptions in the availability of data and impact patient care. The hospital does not have a tracking solution in place to audit whether systems have been updated or to track the length of time between notification of the weakness and patch completion. Since tracking is not in place, the hospital lacks accountability with regard to who is responsible for these activities and the timeline of patching efforts. Which of the following should the hospital do first to mitigate this risk?

  • A. Complete a vulnerability analysis.
  • B. Obtain guidance from the health ISAC.
  • C. Purchase a ticketing system for auditing efforts.
  • D. Ensure CVEs are current.
  • E. Train administrators on why patching is important.
Show Suggested Answer Hide Answer
Suggested Answer: A 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
1 day, 1 hour ago
Selected Answer: C
To mitigate the risk described in the hospital scenario, the most effective first step would be: C. Purchase a ticketing system for auditing efforts. Because The hospital lacks a tracking solution for auditing patching efforts and ensuring accountability. Implementing a ticketing system would immediately address this gap by enabling the hospital to: Track patching efforts: A ticketing system would allow the hospital to create and track tickets for each patching task Improve accountability: By assigning tickets to specific administrators or teams, the system would establish clear responsibility for patching efforts, making it easier to see who is responsible for which tasks and whether those tasks are being completed on time. Provide an audit trail: The ticketing system can maintain a record of patching efforts, ensuring that the hospital can audit the time taken to apply patches and track any delays.
upvoted 1 times
...
light3r1
3 months, 3 weeks ago
Selected Answer: A
A vulnerability analysis will provide a comprehensive understanding of the existing vulnerabilities within the hospital's systems. It identifies the critical areas that need immediate attention and helps prioritize the patching process based on the severity of the vulnerabilities.
upvoted 2 times
...
23169fd
5 months ago
Selected Answer: A
Understanding the Scope: A vulnerability analysis will provide a comprehensive understanding of the existing vulnerabilities within the hospital's systems. It identifies the critical areas that need immediate attention and helps prioritize the patching process based on the severity of the vulnerabilities. Informed Decision-Making: With a detailed vulnerability analysis, the hospital can make informed decisions about which patches need to be applied urgently and which can be scheduled for later, thereby minimizing disruptions to patient care. Foundation for Other Actions: Once the vulnerabilities are clearly identified and documented, the hospital can then implement other necessary steps, such as obtaining guidance from the health ISAC, purchasing a ticketing system, ensuring CVEs are current, and training administrators. These actions will be more effective and targeted when backed by the data from the vulnerability analysis
upvoted 2 times
...
pego99
7 months ago
Selected Answer: A
The hospital should complete a vulnerability analysis I think. The question asks which should be done first to mitigate this risk; a vulnerability analysis would outline the most pressing issues that need to be fixed. After that, a ticketing system could be put in place.
upvoted 3 times
...
cf13076
7 months, 4 weeks ago
Selected Answer: C
To mitigate this risk as per the CompTIA CASP+ certification, the hospital should first: C. Purchase a ticketing system for auditing efforts. Implementing a ticketing system will provide a centralized solution for tracking and monitoring patching activities. It will help in creating accountability by assigning responsibilities for patching tasks, tracking the progress of patch implementations, and ensuring timely completion of patching efforts. A ticketing system can help streamline the patch management process and improve the overall security posture of the hospital's IT systems.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago