A city WLAN vendor releases a fixed AP code train for a known vulnerability, but the municipal change window is next week. What mitigation approach best fits until the upgrade can run?
Select an answer to reveal the explanation.
Short Explanation
Patches are like a scheduled road resurfacing—you plan the night the crews can work, and you put cones out in the meantime. Book the upgrade in the change window and keep eyes (or compensating WIPS rules) on the risk until the blades land. Skipping monitoring because “next week is soon” is how surprises happen.
Full Explanation
Mitigation via patches and upgrades is a primary Domain 2 action, but operational change windows often delay immediate installation. Good practice schedules the vendor fixed code in the authorized window while using interim monitoring or compensating controls to manage residual risk. Ignoring advisories or disabling telemetry increases exposure rather than reducing it.