exam questions

Exam CAS-004 All Questions

View all questions & answers for the CAS-004 exam

Exam CAS-004 topic 1 question 570 discussion

Actual exam question from CompTIA's CAS-004
Question #: 570
Topic #: 1
[All CAS-004 Questions]

A company has grown rapidly in the past few years and has prioritized building new systems over maintaining and patching legacy systems. Now that company growth has slowed, the company is focusing on patching critical legacy systems. Which of the following best describes what the security team should do to address open vulnerabilities?

  • A. Ensure the scan results are compliant with ARF.
  • B. Ensure the output of the scan results contains the CVSSv3 for each vulnerability.
  • C. Ensure IoCs are included in the vulnerability reports for the management team.
  • D. Ensure the CVE is listed in the output of the scan.
Show Suggested Answer Hide Answer
Suggested Answer: D 🗳️

Comments

Chosen Answer:
This is a voting comment (?). It is better to Upvote an existing comment if you don't have anything to add.
Switch to a voting comment New
Bright07
2 weeks, 3 days ago
Selected Answer: B
B NOT D While listing the CVE (Common Vulnerabilities and Exposures) identifier is useful for identifying specific vulnerabilities. However, CVEs alone don't provide a severity score or a means to prioritize vulnerabilities. The CVSS score provides critical context, helping the team assess which vulnerabilities are most urgent and need immediate attention. While the CVE is useful for identifying the vulnerability, it is the CVSS score that is essential for prioritization.
upvoted 1 times
...
Bright07
2 weeks, 3 days ago
Selected Answer: B
CVSSv3 (Common Vulnerability Scoring System version 3) provides a standardized method for assessing the severity of vulnerabilities. The CVSS score helps prioritize vulnerabilities based on their potential impact, taking into account factors like: Exploitability (how easily the vulnerability can be exploited) Impact (the potential damage or disruption if the vulnerability is exploited) Confidentiality, integrity, and availability impacts (how the vulnerability affects data security and system functionality) In the context of patching legacy systems, it's crucial to prioritize vulnerabilities based on their severity and the risk they pose. By ensuring that the vulnerability scan output includes the CVSSv3 scores, the security team can effectively assess which vulnerabilities need to be patched first, focusing on the most critical issues. This also provides a clear, standardized way of presenting vulnerability severity to management and the technical team, helping in decision-making.
upvoted 1 times
...
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.

Upvoting a comment with a selected answer will also increase the vote count towards that answer by one. So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.

SaveCancel
Loading ...
exam
Someone Bought Contributor Access for:
SY0-701
London, 1 minute ago