Q: 2
Two CVEs are discovered on servers in the company's public cloud virtual network. The CVEs are
listed as having an attack vector value of network and CVSS score of 9.0. Which
of the following actions would be the best way to mitigate the vulnerabilities?
Options
Discussion
A tbh, but I'd double-check exam practice and CompTIA docs for this scenario.
Option D Disabling unnecessary open ports should work for network CVEs, right?
I get why some might pick D since closing ports helps with exposure, but that doesn't actually fix the root issue. For CVEs with a known patch and a high CVSS like 9.0, A (patching the OS) is the best step because it directly addresses the vulnerability. D just limits paths in, but the flaw would still exist. Let me know if you see it differently.
Had something like this in a mock, it's A. Direct patching covers the known vulnerability. Disabling ports might help reduce risk but doesn't actually fix the CVE. Pretty sure on A here.
Be respectful. No spam.