Certified Information Systems Security Professional CISSP · Free Practice Question Medium
Question 30
Suobo is the IT director of a rapidly growing tech startup. Given the scale and speed of your company's growth, his CEO has tasked him with ensuring the robustness of your organization's IT security posture. Specifically, the CEO is worried about potential vulnerabilities in your software infrastructure and wants his recommendations on the best types of security controls to mitigate risks. In this context, which of the following types of security controls is likely to be the most effective first line of defense for mitigating vulnerabilities in your software infrastructure?
-
A
Implementing a disaster recovery site for post-attack recovery
-
B
Regularly applying software patches as corrective controls
-
C
Installing an Intrusion Detection System (IDS) as a detective control
-
D
Implementing the principle of least privilege as a preventive control
Reveal correct answer
Correct answer: B
Explanation
The correct answer: Regularly applying software patches as corrective controls is likely to be the most effective first line of defense in this scenario. Software patches are updates released by software vendors to fix known vulnerabilities in their products. Applying these patches regularly can help to mitigate the risk of these known vulnerabilities being exploited. The incorrect answers: Implementing a disaster recovery site for post-attack recovery: While this is an important part of a comprehensive approach to security, it's more about response and recovery than preventing vulnerabilities being exploited in the first place. Installing an Intrusion Detection System (IDS) as a detective control: An IDS can help detect potential intrusions, but it doesn't directly mitigate vulnerabilities in the software infrastructure. It's more about identifying threats rather than preventing them. Implementing the principle of least privilege as a preventive control: This principle, where a user is given the minimum levels of access necessary to perform their job functions, is important for minimizing risk. However, it doesn't directly address vulnerabilities in the software infrastructure.Discussion
Think the marked answer is wrong, or have a better explanation? Share it below — comments appear after review.
You must be logged in to post a comment.
