An organization typically follows a 30-day vendor patch cycle. Active exploitation campaigns currently target VPN appliances. Which prioritization inputs justify overriding the default cycle?
Pick an option to open the notes on all of them.
Key and notes on every option
Key: A
- ACorrect: Internet-facing exposure plus public exploits under active attack put the VPN appliances at real risk now, so emergency patching ahead of the 30-day cycle is justified.
- BBaseline requirements and the routine patch cycle are the default process being overridden, so they can't be the reason to override it.
- CIsolated development systems are the opposite of the exposed VPN edge, and their criticality says nothing about the active campaign.
- DA high CVSS base score with a normal vendor timeline describes severity only; without exposure and active exploitation it doesn't justify breaking the cycle.