ISC2 CISSP Practice Question

During a routine penetration test, your security team discovers a previously unknown zero-day vulnerability in a widely used enterprise software platform deployed throughout your organization. The flaw permits unauthenticated remote code execution on affected servers. Although the team has created a temporary mitigation, it has not yet been rolled out to every system. Which disclosure strategy BEST adheres to responsible and ethical practices?

  • Apply a mitigation to your systems and keep the vulnerability information within your organization

  • Publish technical details of the vulnerability on security blogs and social media to warn users of the software

  • Notify the vendor privately with technical details and allow them time to develop a patch before public disclosure

  • Report the vulnerability to regulatory authorities and then contact the vendor

ISC2 CISSP
Security Assessment and Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot