Memory hook: Inventory, prioritize, fix, verify.
Must remember
You cannot secure unknown assets. Maintain ownership, location, purpose, classification, versions and support status. Apply secure baselines: remove unused software/services, disable default accounts, restrict administration, patch, configure logging and enforce appropriate endpoint protection.
Mobile management can enforce encryption, screen lock, application policy and remote wipe. BYOD raises ownership/privacy boundaries; choose whole-device management versus application/container controls deliberately. Rooted/jailbroken devices weaken assumptions. Wireless, browser, email and document settings can expose different attack surfaces.
Vulnerability scanning identifies potential weaknesses; penetration testing attempts to demonstrate exploitability within authorization and rules of engagement. Credentialed scans can inspect more internal configuration. SAST examines code without running the application; DAST tests running behavior; software composition analysis identifies dependencies and known component issues.
Prioritize using exploitability, exposure, asset value, business impact and active exploitation, not severity alone. CVE identifies a known vulnerability; CVSS scores technical severity; threat intelligence adds context. A low-scoring flaw on a critical exposed identity system can deserve urgent action.
Remediation may mean patching, reconfiguration, removing a component or applying an approved compensating control. Exceptions need owners, expiration and risk acceptance. Test compatibility, maintain a rollback plan, deploy in controlled stages and rescan to verify the issue is resolved. Suppressing an alert is not remediation.
False positive: a reported issue that is not actually present. False negative: an existing issue missed by the test. Confirm with evidence before tuning detection. Sandboxing isolates suspicious code for analysis; a safe analysis environment should not have production access or usable production credentials.
Choose under exam pressure
| Requirement | Choice and reason |
|---|---|
| Find missing updates at scale | Authenticated scanning with appropriate permissions. |
| Prove a finding’s impact | Authorized validation or penetration testing within scope. |
| Cannot immediately patch | Time-bound approved mitigation and tracked risk. |
Traps
- CVSS alone is not business risk.
- An uncredentialed scan may miss issues visible from inside the system.
Active recall
1. Scan or penetration test to inventory suspected flaws?
A vulnerability scan; penetration testing validates selected attack paths.
2. What follows remediation?
Verification/rescanning and documented closure or remaining risk.
3. What is a false negative?
A real issue that the test failed to detect.
4. Why track EOL assets?
Unsupported systems may no longer receive fixes and require replacement or compensating controls.
5. What must a patch exception include?
An accountable owner, risk decision, mitigation and review/expiry plan.