ISC2 Systems Security Certified Practitioner (SSCP) Practice Question
Your company operates a customer-facing website on Amazon EC2 instances in an Auto Scaling group. The security team updates a centralized risk register and relies on CVSS scores to prioritize work. A remote-code-execution flaw with a CVSS v3 base score of 9.8 is announced for the HTTP daemon running on the instances. Which planned response best demonstrates the risk treatment strategy of mitigation?
Apply the vendor patch to the launch template and perform a rolling replacement of all EC2 instances in the Auto Scaling group.
Purchase additional cyber-insurance to cover any losses if the flaw is exploited while keeping the current environment unchanged.
Document the vulnerability in the risk register and defer any remediation until the next quarterly maintenance window.
Migrate the workload to an AWS managed platform that is not affected and retire the current EC2 fleet.
Mitigation reduces the likelihood or impact of a risk by implementing security controls or fixes. Rolling out the vendor patch through the launch template and replacing the affected EC2 instances directly addresses the vulnerability and lowers the probability of exploitation. Migrating to a different managed platform removes the vulnerable service entirely, which is risk avoidance. Purchasing cyber-insurance shifts financial impact to a third party, representing risk transfer. Simply recording the issue and delaying action is risk acceptance because no control is applied to lessen the threat.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What is CVSS v3 base score?
Open an interactive chat with Bash
What is a rolling replacement in an Auto Scaling group?
Open an interactive chat with Bash
What are the different types of risk treatment strategies?
Open an interactive chat with Bash
ISC2 Systems Security Certified Practitioner (SSCP)
Risk Identification, Monitoring and Analysis
Your Score:
Report Issue
Bash, the Crucial Exams Chat Bot
AI Bot
Loading...
Loading...
Loading...
Pass with Confidence.
IT & Cybersecurity Package
You have hit the limits of our free tier, become a Premium Member today for unlimited access.
Military, Healthcare worker, Gov. employee or Teacher? See if you qualify for a Community Discount.
Monthly
$19.99 $11.99
$11.99/mo
Billed monthly, Cancel any time.
$19.99 after promotion ends
3 Month Pass
$44.99 $26.99
$8.99/mo
One time purchase of $26.99, Does not auto-renew.
$44.99 after promotion ends
Save $18!
MOST POPULAR
Annual Pass
$119.99 $71.99
$5.99/mo
One time purchase of $71.99, Does not auto-renew.
$119.99 after promotion ends
Save $48!
BEST DEAL
Lifetime Pass
$189.99 $113.99
One time purchase, Good for life.
Save $76!
What You Get
All IT & Cybersecurity Package plans include the following perks and exams .