mediumMultiple Choice
CISSP Practice Question: Based on the vulnerability scan exhibit, which…
Exhibit
Refer to the exhibit. Vulnerability Scan Report (excerpt): Host: 192.168.1.100 Port: 443 (https) Vulnerability ID: 12345 Plugin: OpenSSL Heartbleed Detection Output: Vulnerable to Heartbleed (CVE-2014-0160) Host: 192.168.1.100 Port: 22 (ssh) Vulnerability ID: 67890 Plugin: SSH Weak MAC Algorithms Output: Server supports weak MAC algorithms (hmac-md5, hmac-sha1-96) Host: 192.168.1.100 Port: 25 (smtp) Vulnerability ID: 11111 Plugin: SMTP Open Relay Output: Server is an open relay.
Based on the vulnerability scan exhibit, which vulnerability should be remediated first?
⚠ Common exam trap
The trap here is that candidates may prioritize SMTP open relay or SSH weak MAC algorithms because they sound like common misconfigurations, but the CISSP exam emphasizes that vulnerabilities with direct, remote exploitation for data disclosure (like Heartbleed) must be remediated first under the principle of risk prioritization.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
OpenSSL Heartbleed vulnerability
The OpenSSL Heartbleed vulnerability (CVE-2014-0160) allows an attacker to read up to 64 KB of memory from a vulnerable server, potentially exposing private keys, session tokens, and passwords. This is a critical information disclosure flaw that requires immediate remediation because it compromises the confidentiality of all encrypted communications. In contrast, the other vulnerabilities are less severe: SSH weak MAC algorithms reduce cryptographic strength but do not directly leak data, and SMTP open relay is a misconfiguration that enables spam but not direct data theft.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
All vulnerabilities equally because they have the same host
Why it's wrong here
Vulnerability prioritization is not solely determined by the host on which they reside. Effective risk management requires evaluating vulnerabilities based on their severity, exploitability, potential impact, and the criticality of the affected asset, not just their presence on the same system. Different vulnerabilities, even on the same host, pose varying levels of risk that demand distinct remediation timelines and resources.
- ✗
SSH weak MAC algorithms
Why it's wrong here
While the use of weak Message Authentication Code (MAC) algorithms in SSH is a legitimate security concern, potentially allowing for data tampering or session hijacking under specific conditions, it is generally considered less critical than a vulnerability like Heartbleed. Weak MACs typically require an active attacker to intercept and modify traffic, whereas Heartbleed allowed for passive information disclosure of sensitive data directly from memory without authentication.
- ✗
SMTP open relay
Why it's wrong here
An SMTP open relay, which allows unauthenticated third parties to send email through the server, is a medium-severity vulnerability primarily associated with facilitating spam and phishing attacks. While it can lead to reputational damage, IP blacklisting, and resource misuse, it typically does not directly expose sensitive system memory or critical data in the same manner as a severe memory disclosure flaw. Its impact is generally external and operational rather than direct data compromise.
- ✓
OpenSSL Heartbleed vulnerability
Why this is correct
The OpenSSL Heartbleed vulnerability (CVE-2014-0160) is a critical memory disclosure flaw that allowed attackers to read up to 64KB of memory from affected servers, potentially exposing private keys, user credentials, and other sensitive data without leaving a trace. Its high severity stems from its widespread impact on internet services, ease of exploitation, and the direct compromise of confidentiality, making it a top priority for immediate remediation.
Quick reference
Access Control Model Comparison
| Model | Acronym | Who Controls Access? | Best For |
|---|---|---|---|
| Discretionary Access Control | DAC | Resource owner | Small teams, file shares |
| Mandatory Access Control | MAC | System / security labels | Classified govt / military |
| Role-Based Access Control | RBAC | Administrator (via roles) | Enterprise environments |
| Attribute-Based Access Control | ABAC | Policy engine (user + resource attributes) | Fine-grained, dynamic policies |
| Rule-Based Access Control | RuBAC | System rules / ACLs | Firewall rules, network ACLs |
Go deeper
Related to this question
Learn chapter
Asset Security: Privacy and Data Retention
Key term
MAC
MAC (Media Access Control) is a unique hardware identifier assigned to network interfaces for communication on a local network segment.
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.