A security analyst is investigating a recent security incident where an attacker gained unauthorized access to a server. The analyst suspects the attacker used a known vulnerability in an outdated web application. Which of the following are the MOST appropriate steps to mitigate this vulnerability in the future? (Choose two.)
Regular patching ensures that known vulnerabilities are remediated promptly. In this scenario, the outdated web application likely had a publicly known exploit that could have been fixed by applying vendor patches. A formal patch management process includes inventory, testing, and deployment, reducing the window of exposure and preventing similar incidents.
Why this answer
The most effective ways to mitigate a known vulnerability in an outdated web application are to patch it regularly and to proactively identify vulnerabilities through scanning and remediation. These steps directly address the root cause by eliminating the vulnerable code. Other options like WAF, segmentation, or encryption are compensating controls or defense-in-depth measures, but they do not fix the underlying flaw.
Exam trap
The trap here is selecting compensating controls like WAF or segmentation as primary mitigations, when the question asks for steps to mitigate the vulnerability itself.