Deal of The Day! Hurry Up, Grab the Special Discount - Save 25% - Ends In 00:00:00 Coupon code: SAVE25
Welcome to Pass4Success

- Free Preparation Discussions

PECB ISO-IEC-27035-Lead-Incident-Manager Exam - Topic 1 Question 9 Discussion

How should vulnerabilities lacking corresponding threats be handled?
C) They may not require controls but should be analyzed and monitored for changes
A) They still require controls and should be promptly addressed
B) They should be disregarded as they pose no risk

PECB ISO-IEC-27035-Lead-Incident-Manager Exam - Topic 1 Question 9 Discussion

Actual exam question for PECB's ISO-IEC-27035-Lead-Incident-Manager exam
Question #: 9
Topic #: 1
[All ISO-IEC-27035-Lead-Incident-Manager Questions]

How should vulnerabilities lacking corresponding threats be handled?

Show Suggested Answer Hide Answer
Suggested Answer: C

Contribute your Thoughts:

0/2000 characters
Christa
7 hours ago
I think A is the best choice. Vulnerabilities can become threats anytime.
upvoted 0 times
...
Anisha
5 days ago
Totally agree with A! Vulnerabilities can lead to unexpected issues.
upvoted 0 times
...
Rolf
11 days ago
Wait, how can we just ignore vulnerabilities? That sounds off.
upvoted 0 times
...
Tawna
16 days ago
C) I think monitoring is smart, but controls might still be needed.
upvoted 0 times
...
Benton
2 months ago
B) Disregarding them seems risky to me.
upvoted 0 times
...
Dana
2 months ago
A) definitely needs controls! Better safe than sorry.
upvoted 0 times
...
Katie
3 months ago
I’m a bit confused; I thought we learned that all vulnerabilities should be treated seriously, but I’m not sure if that means they need controls or just monitoring.
upvoted 0 times
...
Venita
3 months ago
I recall a practice question where we had to decide if vulnerabilities should be addressed, and I think the answer was to analyze them, which sounds like C again.
upvoted 0 times
...
Sherill
3 months ago
I’m not entirely sure, but I feel like we discussed that even if there’s no immediate threat, we shouldn’t just ignore vulnerabilities. Could it be A?
upvoted 0 times
...
Cassi
3 months ago
I think I remember that vulnerabilities without threats still need some level of monitoring, so maybe option C is the right choice?
upvoted 0 times
...

Save Cancel