A jump host in a hybrid SOC is quarantined after EDR detects malware execution. Forensics show the malware arrived through an unpatched remote access application exposed to the internet. The analyst must recommend remediation that fixes the root cause rather than only the symptom. Which action best meets that requirement?
Select an answer to reveal the explanation.
Short Explanation
Think of it like this: malware is the fire, the unpatched remote access app is the open door. You have to shut the door, not just mop up the water. Quarantine and C2 blocks help, but they don't fix the weakness that let the incident happen.
Full Explanation
Root-cause remediation means eliminating the condition that allowed the incident to occur, not merely cleaning the artifact left behind. When malware execution is the observed symptom and an unpatched remote access application is the exploited weakness, the durable fix is to remove that weakness by applying the vendor patch or upgrading the affected software, then verifying the service is no longer exploitable. Containment actions such as isolating the endpoint and deleting malicious files are necessary during response, but they do not change the underlying vulnerability; the same host or another host running the same software could be compromised again. Blocking command-and-control traffic reduces attacker control and exfiltration opportunities, yet it addresses post-compromise communication rather than the entry mechanism. Credential resets are useful when accounts are suspected of misuse or lateral movement, but they do not repair an exploited software flaw. Exam caveat: CS0-004 often asks you to separate containment, eradication, and recovery from root-cause remediation; the correct answer should target the weakness that enabled the event. Operational check: after patching, rerun a vulnerability scan against the remote access service and confirm the relevant finding is closed before returning the system to production.