easyMultiple Choice
CISSP Practice Question: An internet-facing Apache web server is running…
Exhibit
CVE-2023-1234 - Apache HTTP Server 2.4.49 - Path Traversal - Severity: Critical - Exploit Available: Yes - Plugin Output: The remote web server is running Apache HTTP Server version 2.4.49 which is vulnerable to a path traversal attack.
An internet-facing Apache web server is running version 2.4.49 and is vulnerable to CVE-2021-41773 path traversal. What is the most urgent remediation?
⚠ Common exam trap
ISC2 exams focus on the most complete and effective remediation. A WAF rule or configuration change may reduce exposure but does not fix the underlying vulnerable code; the most urgent action is upgrading to a fully patched version such as Apache 2.4.51 or later.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Upgrade to Apache 2.4.51 or later
CVE-2021-41773 was patched in Apache 2.4.50, but CVE-2021-42013 demonstrated an incomplete fix affecting 2.4.50. The complete remediation is to upgrade to Apache 2.4.51 or later, which closes the path traversal and RCE vector. Disabling directory listing, recompiling with security flags, or adding a WAF rule are compensating controls, not the most urgent remediation.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Disable directory listing
Why it's wrong here
Disabling directory listing prevents attackers from viewing a list of files within a directory if they navigate to it directly. However, a path traversal vulnerability, such as those found in Apache HTTP Server 2.4.49, exploits how the server processes manipulated file paths (e.g., using `../` sequences) to access arbitrary files outside the intended web root. This attack vector is entirely independent of whether the server is configured to display directory contents, making directory listing irrelevant to preventing path traversal.
- ✓
Upgrade to Apache 2.4.51 or later
Why this is correct
Upgrading to Apache HTTP Server version 2.4.50 or later is the most direct and effective remediation for known path traversal vulnerabilities, specifically CVE-2021-41773 and CVE-2021-42013. These patched versions contain specific code fixes that correctly normalize paths and prevent directory traversal sequences from being misinterpreted by the server's core logic. This approach permanently resolves the vulnerability at its source by eliminating the underlying software flaw.
- ✗
Recompile Apache with security flags
Why it's wrong here
Recompiling Apache with generic "security flags" is not a standard or effective remediation for a specific, known path traversal vulnerability like those affecting Apache HTTP Server 2.4.49. Such vulnerabilities stem from fundamental flaws in path normalization logic within the server's core code, not from compiler options or build configurations. While recompilation might be part of a custom hardening process, it would not inherently fix a logic bug without specific source code modifications, which are already provided in official patches.
- ✗
Apply a WAF rule to block path traversal attempts
Why it's wrong here
Applying a Web Application Firewall (WAF) rule to block path traversal attempts, while a valuable compensating control, does not directly fix the underlying vulnerability within the Apache HTTP Server itself. WAFs operate by inspecting and filtering network traffic based on predefined patterns and heuristics, which can sometimes be bypassed by sophisticated attackers using obfuscation techniques or novel attack vectors. Therefore, a WAF provides an additional layer of defense but is not considered the primary or most permanent solution compared to patching the vulnerable software.
Go deeper
Related to this question
About these practice questions
Courseiva writes every CISSP question from scratch — 816 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CISSP practice question is part of Courseiva's free ISC2 certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CISSP exam.