When a zero-day vulnerability is discovered in a critical system, the most crucial action is to implement compensating controls immediately as patches or direct fixes are often not available. These controls can mitigate the risk associated with the vulnerability until a permanent solution is devised. Notifying stakeholders and reconfiguring other security settings are important, but they do not directly mitigate the immediate risk caused by the zero-day vulnerability.
Ask Bash
Bash is our AI bot, trained to help you pass your exam. AI Generated Content may display inaccurate information, always double-check anything important.
What are compensating controls?
Open an interactive chat with Bash
What is a zero-day vulnerability?
Open an interactive chat with Bash
Why is notifying stakeholders not the most crucial action?