exam questions

Exam CS0-003 All Questions

View all questions & answers for the CS0-003 exam

Exam CS0-003 topic 1 question 252 discussion

Actual exam question from CompTIA's CS0-003
Question #: 252
Topic #: 1
[All CS0-003 Questions]

A security analyst is working on a server patch management policy that will allow the infrastructure team to be informed more quickly about new patches. Which of the following would most likely be required by the infrastructure team so that vulnerabilities can be remediated quickly? (Choose two.)

  • A. Hostname
  • B. Missing KPI
  • C. CVE details
  • D. POC availabilty
  • E. IoCs
  • F. npm identifier
Show Suggested Answer Hide Answer
Suggested Answer: AC 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
whoamyou
Highly Voted 7 months ago
Selected Answer: AC
The question doesn't mention anything about deciding which patch should be prioritized, so POC availability doesn't seem relevant. Since the question asks, 'Which of the following would most likely be required by the infrastructure team so that vulnerabilities can be remediated quickly?' I believe the correct answers are Hostname and CVE details. The hostname tells the infrastructure team which host needs to be remediated, and the CVE provides information on how to fix the vulnerability. Without the hostname, they'd have to check all assets, which would slow things down.
upvoted 13 times
...
TurboMor
Highly Voted 7 months, 4 weeks ago
Why are you choosing POC availability or IoCs? How would that help the infrastructure team remediate faster? I would go with A and C... The infrastructure team needs to know which patch to apply (CVE details) and where to it (Hostname).
upvoted 10 times
...
Serac
Most Recent 6 months, 2 weeks ago
Selected Answer: AC
I think knowing the CVE and the affected host name would help with most.
upvoted 1 times
...
Chiniwini
9 months ago
Selected Answer: CD
C. CVE details: CVE (Common Vulnerabilities and Exposures) details provide specific information about known vulnerabilities, including their nature, potential impact, and references to patches or mitigation strategies. This information is critical for understanding the urgency and the specific steps needed to address each vulnerability. D. POC availability: Proof of Concept (PoC) availability demonstrates how a vulnerability can be exploited. Having PoC information helps the infrastructure team understand the practical implications of a vulnerability and prioritize patches based on the severity and ease of exploitation.
upvoted 3 times
Chiniwini
8 months, 4 weeks ago
After reviewing I believe C and E: IoC (Indicators of Comprise) would be correct. IoC are more critical in the initial stage of vulnerability mitigation compared to POC Proof of Concept
upvoted 5 times
...
...
saylar478
9 months, 3 weeks ago
Selected Answer: CE
CE for me are the most suitables answers
upvoted 5 times
...
maggie22
9 months, 4 weeks ago
Selected Answer: CE
POC (Proof of Concept) availability may be useful for understanding how vulnerabilities can be exploited, but it is not essential for the immediate prioritization and application of patches.
upvoted 4 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago