A security administrator is reviewing patch management practices and finds that critical patches are taking an average of 45 days to deploy after release. A threat actor is known to exploit new vulnerabilities within 7 days of patch release. What risk does this gap create and what is the appropriate control?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because when attackers exploit vulnerabilities within 7 days and patches take 45 days, a 38-day exploitation window exists for known vulnerabilities; reducing the critical patch SLA and prioritizing highest-risk systems directly closes this gap. A is wrong because attackers specifically target recently patched vulnerabilities because many organizations patch slowly, making this window highly targeted.
Full explanation below image
Full Explanation
B is correct because when attackers exploit vulnerabilities within 7 days and patches take 45 days, a 38-day exploitation window exists for known vulnerabilities; reducing the critical patch SLA and prioritizing highest-risk systems directly closes this gap. A is wrong because attackers specifically target recently patched vulnerabilities because many organizations patch slowly, making this window highly targeted. C is wrong because a 45-day cycle for critical patches is too slow given current threat actor exploitation timelines; industry best practice is 7-30 days for critical. D is wrong because disabling vulnerability disclosure is impractical, unethical, and would harm the security community's ability to coordinate defenses.