ISC2 CISSP Practice Question

Your security team discovers a zero-day vulnerability in a widely-used enterprise software platform that your organization uses. The vulnerability allows unauthenticated code execution. Your team has developed a mitigation but hasn't yet applied it across all systems. What is the most appropriate ethical disclosure approach?

  • Report the vulnerability to regulatory authorities and then contact the vendor

  • Publish technical details of the vulnerability on security blogs and social media to warn users of the software

  • Notify the vendor privately with technical details and allow them time to develop a patch before public disclosure

  • Apply a mitigation to your systems and keep the vulnerability information within your organization

ISC2 CISSP
Security Assessment and Testing
Your Score:
Settings & Objectives
Random Mixed
Questions are selected randomly from all chosen topics, with a preference for those you haven’t seen before. You may see several questions from the same objective or domain in a row.
Rotate by Objective
Questions cycle through each objective or domain in turn, helping you avoid long streaks of questions from the same area. You may see some repeat questions, but the distribution will be more balanced across topics.

Check or uncheck an objective to set which questions you will receive.

Bash, the Crucial Exams Chat Bot
AI Bot