Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

Cisco 350-201 Exam - Topic 8 Question 104 Discussion

A company recently completed an internal audit and discovered that there is CSRF vulnerability in 20 of its hosted applications. Based on the audit, which recommendation should an engineer make for patching?
A) Identify the business applications running on the assets
B) Update software to patch third-party software
C) Validate CSRF by executing exploits within Metasploit
D) Fix applications according to the risk scores

Cisco 350-201 Exam - Topic 8 Question 104 Discussion

Actual exam question for Cisco's 350-201 exam
Question #: 104
Topic #: 8
[All 350-201 Questions]

A company recently completed an internal audit and discovered that there is CSRF vulnerability in 20 of its hosted applications. Based on the audit, which recommendation should an engineer make for patching?

Show Suggested Answer Hide Answer
Suggested Answer: A

Contribute your Thoughts:

0/2000 characters
Gabriele
9 months ago
Identifying business applications first makes sense!
upvoted 0 times
...
Lizbeth
9 months ago
Wait, are we sure Metasploit is the right tool for this?
upvoted 0 times
...
Xuan
10 months ago
I think updating third-party software is crucial too.
upvoted 0 times
...
Ilene
10 months ago
Definitely need to fix those based on risk scores.
upvoted 0 times
...
Eun
10 months ago
Wow, 20 apps with CSRF issues? That's a lot!
upvoted 0 times
...
Kati
10 months ago
Validating CSRF with Metasploit sounds like a good idea, but I wonder if it's more of a testing step rather than a patching recommendation.
upvoted 0 times
...
Wilda
11 months ago
I feel like we practiced a question about patching third-party software, but I'm not sure if that's the best approach for CSRF specifically.
upvoted 0 times
...
Shenika
11 months ago
I'm not entirely sure, but I think identifying the business applications first could help in understanding the impact of the vulnerabilities.
upvoted 0 times
...
Lashaunda
11 months ago
I remember we discussed prioritizing fixes based on risk scores in class. That seems relevant here.
upvoted 0 times
...
Lindsey
11 months ago
I've got a good strategy for this. I'll start by considering the risk scores and then determine the best way to fix the applications.
upvoted 0 times
...
Tran
11 months ago
I'm a little confused by the wording of the question. I'll need to re-read it a few times to make sure I understand what they're asking.
upvoted 0 times
...
Margart
11 months ago
Okay, let's see. The key here is to focus on the best way to patch the vulnerabilities, not just identify them.
upvoted 0 times
...
Magdalene
11 months ago
Hmm, I'm a bit unsure about this. I'll need to think through the different options carefully.
upvoted 0 times
...
Bobbie
11 months ago
This looks like a straightforward question on patching CSRF vulnerabilities. I think I can handle this one.
upvoted 0 times
...
Felix
1 year ago
Updating third-party software might be a good start, but it's not going to fix the specific CSRF issues in the company's applications. D is definitely the most comprehensive solution.
upvoted 0 times
Lashon
1 year ago
A: Identifying the business applications running on the assets is also important.
upvoted 0 times
...
Lonna
1 year ago
B: I agree, that seems like the most thorough approach.
upvoted 0 times
...
Mel
1 year ago
A: We should fix applications according to the risk scores.
upvoted 0 times
...
...
Fallon
1 year ago
Haha, I'm pretty sure the auditors wouldn't appreciate us trying to 'exploit' the vulnerability. Let's stick to the safe and responsible options.
upvoted 0 times
German
1 year ago
Haha, I'm pretty sure the auditors wouldn't appreciate us trying to 'exploit' the vulnerability. Let's stick to the safe and responsible options.
upvoted 0 times
...
Belen
1 year ago
D) Fix applications according to the risk scores
upvoted 0 times
...
Maryln
1 year ago
B) Update software to patch third-party software
upvoted 0 times
...
Fannie
1 year ago
D) Fix applications according to the risk scores
upvoted 0 times
...
Alecia
1 year ago
B) Update software to patch third-party software
upvoted 0 times
...
Wei
1 year ago
A) Identify the business applications running on the assets
upvoted 0 times
...
Dulce
1 year ago
A) Identify the business applications running on the assets
upvoted 0 times
...
...
Ruthann
1 year ago
I'm not sure Metasploit is the best tool for validating CSRF. That seems a bit risky, especially in a production environment.
upvoted 0 times
...
Lelia
1 year ago
Option D is the way to go. Patching the applications based on risk scores is the most effective approach to addressing the CSRF vulnerability.
upvoted 0 times
...
Theola
1 year ago
But shouldn't we also identify the business applications running on the assets first?
upvoted 0 times
...
Jose
1 year ago
I agree with Allene, it's important to prioritize based on risk.
upvoted 0 times
...
Allene
1 year ago
We should fix applications according to the risk scores.
upvoted 0 times
...

Save Cancel