Study. uk . com
  1. Home
  2. All questions
  3. Question 111

CompTIA Security+ study material · question 111 of 611

An upgrade would fix a vulnerability, but the new version's cryptographic modules are not yet FIPS-validated and the organisation must use validated modules. What does this illustrate?

  1. That FIPS validation is optional for private organisations
  2. That the vulnerability should be reclassified as low
  3. That patching decisions are not purely technical
  4. That the vendor is liable for the delay
Show the answer

Answer: C. That patching decisions are not purely technical

An upgrade can break a compliance requirement, so the response has to weigh both obligations.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.1 Risk Responses

Challenge yourself on this topic → Study as cards