hardMultiple Choice
CISM Practice Question: During a security incident, the incident response…
During a security incident, the incident response team discovers that an attacker used a previously unknown vulnerability (zero-day) in a widely used software. Which action should the team take to address this vulnerability in the short term?
⚠ Common exam trap
Watch out — candidates often confuse 'short-term' with 'permanent' solutions, mistakenly choosing D (vendor patch) as the immediate action, when in fact the correct short-term response is to implement a compensating control like a virtual patch to reduce risk while awaiting the vendor's official fix.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a virtual patch through an intrusion prevention system (IPS)
A virtual patch via an IPS provides immediate, temporary protection against a zero-day vulnerability by inspecting traffic for exploit patterns or anomalous behavior and blocking malicious payloads before they reach the vulnerable software. This buys time for the organization to assess the risk and plan a permanent fix without disrupting operations, as the IPS can be updated with signatures or rules specific to the newly discovered vulnerability.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Implement a virtual patch through an intrusion prevention system (IPS)
Why this is correct
A virtual patch via IPS enforces signature or behavioural rules at the network layer, blocking exploitation attempts against the unpatched zero-day without modifying the vulnerable software itself. This satisfies the short-term constraint, since no vendor fix exists yet, buying time until the vendor releases and the organisation deploys a permanent patch.
- ✗
Recompile the software with additional security controls
Why it's wrong here
Recompiling third-party software is impossible without its source code, and rebuilding it does not remove the unknown flaw. It is tempting because recompilation with hardened flags is a genuine mitigation for in-house applications whose source the organisation controls, but not for vendor binaries.
- ✗
Immediately disable the software across the organization
Why it's wrong here
Disabling widely used software halts business operations across the organisation, which is disproportionate containment for a zero-day when compensating controls can restrict the vulnerable vector. It is tempting as total removal guarantees the flaw cannot be exploited, and would suit a narrowly scoped, non-critical tool.
- ✗
Deploy a vendor patch as soon as it becomes available
Why it's wrong here
No patch exists for a zero-day, so waiting for the vendor leaves the vulnerability exploitable throughout the short term. It is tempting because patching is the definitive fix once released, and would be correct for a known vulnerability with an available update.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISM question from scratch — 924 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISM practice question is part of Courseiva's free ISACA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISM exam.