A vulnerability scanner reports the same vulnerable open-source library in five web applications. The applications are owned by different teams, but all depend on the same shared platform package. Which remediation approach is most efficient?
Select an answer to reveal the explanation.
Short Explanation
Think of it like patching one shared library instead of five separate copies. You fix the upstream dependency once, then verify each app still works. That keeps you from chasing the same bug in every ticket.
Full Explanation
When the same open-source component appears in several applications, the root cause is a shared dependency, not five independent defects. Centralizing the upgrade in the platform baseline reduces duplicate work, prevents version drift, and lets validation focus on integration risk rather than repeated patching. A team-by-team ticketing approach wastes effort because each team must discover, test, and deploy the same fix independently; it also increases the chance of missed systems or inconsistent versions. A compensating network control can reduce exposure temporarily, but it does not remove the vulnerable code path and should only delay remediation when patching is genuinely impossible. Replacing each application is disproportionate because the vulnerability exists in a dependency, not in the entire business function, and replacement introduces new risk and cost. Exam caveat: prioritize by shared root cause and blast radius, not by the number of scanner findings. Operational check: map every affected service to the package name and version, upgrade the shared package once, then rerun the scan and functional tests for each consumer.