Courseiva
mediumMultiple Choice

CISSP Practice Question: Based on the vulnerability scan exhibit, which…

Exhibit

Refer to the exhibit.

Vulnerability Scan Report (excerpt):
Host: 192.168.1.100
Port: 443 (https)
Vulnerability ID: 12345
Plugin: OpenSSL Heartbleed Detection
Output: Vulnerable to Heartbleed (CVE-2014-0160)

Host: 192.168.1.100
Port: 22 (ssh)
Vulnerability ID: 67890
Plugin: SSH Weak MAC Algorithms
Output: Server supports weak MAC algorithms (hmac-md5, hmac-sha1-96)

Host: 192.168.1.100
Port: 25 (smtp)
Vulnerability ID: 11111
Plugin: SMTP Open Relay
Output: Server is an open relay.

Based on the vulnerability scan exhibit, which vulnerability should be remediated first?

⚠ Common exam trap

The trap here is that candidates may prioritize SMTP open relay or SSH weak MAC algorithms because they sound like common misconfigurations, but the CISSP exam emphasizes that vulnerabilities with direct, remote exploitation for data disclosure (like Heartbleed) must be remediated first under the principle of risk prioritization.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

OpenSSL Heartbleed vulnerability

The OpenSSL Heartbleed vulnerability (CVE-2014-0160) allows an attacker to read up to 64 KB of memory from a vulnerable server, potentially exposing private keys, session tokens, and passwords. This is a critical information disclosure flaw that requires immediate remediation because it compromises the confidentiality of all encrypted communications. In contrast, the other vulnerabilities are less severe: SSH weak MAC algorithms reduce cryptographic strength but do not directly leak data, and SMTP open relay is a misconfiguration that enables spam but not direct data theft.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    All vulnerabilities equally because they have the same host

    Why it's wrong here

    Vulnerability prioritization is not solely determined by the host on which they reside. Effective risk management requires evaluating vulnerabilities based on their severity, exploitability, potential impact, and the criticality of the affected asset, not just their presence on the same system. Different vulnerabilities, even on the same host, pose varying levels of risk that demand distinct remediation timelines and resources.

  • ✗

    SSH weak MAC algorithms

    Why it's wrong here

    While the use of weak Message Authentication Code (MAC) algorithms in SSH is a legitimate security concern, potentially allowing for data tampering or session hijacking under specific conditions, it is generally considered less critical than a vulnerability like Heartbleed. Weak MACs typically require an active attacker to intercept and modify traffic, whereas Heartbleed allowed for passive information disclosure of sensitive data directly from memory without authentication.

  • ✗

    SMTP open relay

    Why it's wrong here

    An SMTP open relay, which allows unauthenticated third parties to send email through the server, is a medium-severity vulnerability primarily associated with facilitating spam and phishing attacks. While it can lead to reputational damage, IP blacklisting, and resource misuse, it typically does not directly expose sensitive system memory or critical data in the same manner as a severe memory disclosure flaw. Its impact is generally external and operational rather than direct data compromise.

  • ✓

    OpenSSL Heartbleed vulnerability

    Why this is correct

    The OpenSSL Heartbleed vulnerability (CVE-2014-0160) is a critical memory disclosure flaw that allowed attackers to read up to 64KB of memory from affected servers, potentially exposing private keys, user credentials, and other sensitive data without leaving a trace. Its high severity stems from its widespread impact on internet services, ease of exploitation, and the direct compromise of confidentiality, making it a top priority for immediate remediation.

Quick reference

Access Control Model Comparison

ModelAcronymWho Controls Access?Best For
Discretionary Access ControlDACResource ownerSmall teams, file shares
Mandatory Access ControlMACSystem / security labelsClassified govt / military
Role-Based Access ControlRBACAdministrator (via roles)Enterprise environments
Attribute-Based Access ControlABACPolicy engine (user + resource attributes)Fine-grained, dynamic policies
Rule-Based Access ControlRuBACSystem rules / ACLsFirewall rules, network ACLs

About these practice questions

Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.