Skip to content

FRM Part II · FRM Exam Part II · Case Study: Cyberthreats and Information Security Risks

A bank's security team discovers that a critical vulnerability patch was released by the software vendor four months ago but was never applied to an internet-facing server, which attackers then used to gain entry. Which control failure does this MOST directly illustrate?

This is a failure of vulnerability and patch management. The vendor had already released a fix, yet the bank did not apply it to an exposed server, leaving a known weakness open for attackers. The other controls listed would not have closed that specific gap.

  1. AWeak vulnerability and patch managementCorrect
  2. BInadequate encryption of data at rest
  3. CInsufficient physical access controls
  4. DLack of a business continuity site

Explanation

A known fix existed but was not deployed, so the weakness lay in the patch and vulnerability management process. Encryption, physical access and continuity sites would not address an unpatched, exposed server.

Did you get it right without looking?

One question tells you little. A timed set on Case Study: Cyberthreats and Information Security Risks shows your real accuracy, how long you take and where you lose marks.

More Case Study: Cyberthreats and Information Security Risks questions