Which of the following steps should be taken before mitigating a vulnerability in a production server?
Choose an answer
Tap an option to check your answer.
Correct answer: Refer to the change management policy..
Why this is the answer
Before mitigating a vulnerability in a production server, it is crucial to refer to the change management policy. This policy outlines the procedures for implementing changes to production systems, ensuring that modifications are properly documented, tested, approved, and communicated to avoid unintended disruptions or new vulnerabilities. Escalating to the SDLC team is not the immediate next step; the SDLC team is involved in development, not necessarily the operational mitigation of a discovered vulnerability. Using the IR plan is for incident response, which occurs after a security incident, not typically before mitigating a known vulnerability. Performing a risk assessment to classify the vulnerability is a good practice, but the change management policy dictates the process for implementing the mitigation itself, making it the most direct and necessary step before proceeding with actual changes.
Pass your exam — without the endless answer hunt
Get every verified question and explanation for this exam in one place, and save hours of prep. 1,000+ certifications · 20+ languages · free to start.
Pass your exam faster → No card needed