During a routine automated compliance scan, a security operations team discovers a critical zero-day vulnerability in a core software dependency running on legacy Linux application hosts. Vendor testing reveals that applying the official patch breaks custom enterprise middleware dependencies, causing service instability during canary testing. Which of the following actions represents the MOST appropriate immediate strategy to maintain security posture without compromising service availability?
- Apply virtual patching rules at the intrusion prevention system (IPS) or web application firewall (WAF) layer while testing a updated middleware revision in a staging environment.Cevap
- BOverride the canary failure warnings and force the vendor patch deployment across production nodes to meet immediate vulnerability remediation SLAs.
- CModify the production server configuration baselines to permanently disable the vulnerable middleware module directly on live hosts.
- DReclassify the affected assets as non-critical in the configuration management database (CMDB) to exclude them from automated vulnerability enforcement.
Cevap
Implement virtual patching at the perimeter (IPS/WAF) as a temporary compensating control while validating middleware stability in staging.
Virtual patching utilizes network-level or application-layer security controls (such as IPS signatures or WAF rules) to detect and block exploitation attempts targeting a specific vulnerability before the underlying system software is patched. This serves as an ideal temporary compensating control when vendor patches introduce breaking changes to custom middleware, allowing the organization to mitigate risk immediately while engineers resolve software dependencies in a isolated staging environment.
Adım Adım Çözüm
Anahtar Kavram
Virtual Patching and Compensating Controls in Patch Management
Tahmini Süre:2m 0s