CompTIA Study Materials
AWS Study Materials
AWS Cloud Practitioner AWS Cloud Practitioner
AWS Cloud Practitioner CLF-C02
Microsoft Study Materials
Microsoft Azure Fundamentals Microsoft Azure Fundamentals
Microsoft Azure Fundamentals AZ-900

Free CompTIA Security+ SY0-601 Practice Question

Your employer has a large team of software developers with constantly changing codebases for dozens of internal applications. As a part of change control any code changes go through an automated vulnerability scanning process which checks for known vulnerabilities in frameworks, programming languages, dependencies and the code itself. Due to business pressure these scans have been largely ignored and there are currently over a thousand issues found by the automated scanning. You are tasked with working with the developers and remedying 100% of the issues. What should you do next?

  • Organize the vulnerabilities by criticality and begin planning for solutions for the most critical vulnerabilities first

  • Implement an approval step for all code changes that requires no security issues prior to updates

  • Stop all deployments, code changes and updates until the vulnerabilities are fixed

  • Identify any false positives to reduce the number of items to remediate

This question is for objective:
Governance, Risk, and Compliance
Your Score:
Governance, Risk, and Compliance
Architecture and Design
Implementation
Operations and Incident Response
Attacks, Threats, and Vulnerabilities