A cloud application used by an organization is found to have a serious vulnerability. After assessing the risk, which of the following would be the information security manager's BEST course of action?
A.
Instruct the vendor to conduct penetration testing.
B.
Suspend the connection to the application in the firewall.
C.
Initiate the organization’s incident response process.
D.
Report the situation to the business owner of the application.
D - When a serious vulnerability is identified but no incident has occurred, the best course of action is to report the situation to the business owner of the application (Option D).
Although the situation involves a vulnerability detection rather than an active incident, the initiation of the incident response process is still the most prudent course of action. Reporting the situation to the business owner of the application could be a step in the incident response plan.
It is D, not C. No incident has occurred just a vulnerability has been identified. If an incident had occurred then the answer would be C. But seeing as how it was identified the answer is D.
I would go with D. The cloud application used by the org sounds like a third party off the shelf app. You wouldn't initiate your orgs IR process for a third party cloud solution
Although you are not wrong, remember who is responsible for the applications. There is nothing you can do if the app is not your asset. Confusing but I get where you answer is coming from.
upvoted 2 times
...
...
Log in to ExamTopics
Sign in:
Community vote distribution
A (35%)
C (25%)
B (20%)
Other
Most Voted
A voting comment increases the vote count for the chosen answer by one.
Upvoting a comment with a selected answer will also increase the vote count towards that answer by one.
So if you see a comment that you already agree with, you can upvote it instead of posting a new comment.
Booict
2Â months, 3Â weeks agojcisco123
10Â months agoblehbleh
10Â months, 2Â weeks agooluchecpoint
1Â year, 2Â months agoGoseu
1Â year, 4Â months agoddharia94
1Â year, 4Â months agorichck102
1Â year, 4Â months agoJae_kes
1Â year, 5Â months agochanke
1Â year, 5Â months ago