Study. uk . com
  1. Home
  2. All questions
  3. Question 28

CompTIA Security+ study material · question 28 of 611

A vendor will not patch a flaw in a product the organisation uses. Which two of the following are recognised risk responses in this situation? Choose two.

  1. Isolate the asset behind segmentation to reduce exploitation
  2. Re-score the vulnerability lower so it drops off the report
  3. Decommission the asset so the attack surface disappears
  4. Record the finding as a false positive
Show the answer

Answer: A. Isolate the asset behind segmentation to reduce exploitation
C. Decommission the asset so the attack surface disappears

Isolation is mitigation and decommissioning is avoidance. Re-scoring or reclassifying the finding changes the report, not the risk.

Source: NIST SP 800-40 Rev. 4 (NIST) — SP 800-40 Rev. 4 § 2.1 Risk Responses

Challenge yourself on this topic → Study as cards