A security engineer finds that 30% of workstations have not received critical OS patches after 60 days. The patches address an RCE vulnerability actively exploited in the wild. What is the BEST immediate remediation approach?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because active exploitation of a critical RCE vulnerability requires urgent action. Force-deploying patches addresses the vulnerability directly while compensating controls protect unpatched systems until remediation is complete.
Full explanation below image
Full Explanation
B is correct because active exploitation of a critical RCE vulnerability requires urgent action. Force-deploying patches addresses the vulnerability directly while compensating controls protect unpatched systems until remediation is complete. A is wrong because email reminders are too slow for an actively exploited critical vulnerability. C is wrong because 30% unpatched for an actively exploited RCE represents a significant number of vulnerable entry points. D is wrong because waiting for a scheduled window leaves systems exposed when active exploitation is confirmed.