A penetration tester submits a test report recommending remediation for a high-severity finding. The client's development team says the fix will take 6 months to implement. What should the client implement in the meantime?
Select an answer to reveal the explanation.
Short Explanation and Infographic
Here's the deal — b is correct because compensating controls reduce the risk exposure of a known vulnerability during the remediation period; WAF rules can block specific exploit patterns, network controls can limit who can reach the vulnerable service, and enhanced monitoring provides early warning of exploitation attempts. A is wrong because accepting risk without compensating controls is appropriate only after evaluating and implementing all practical risk reduction options.
Full explanation below image
Full Explanation
B is correct because compensating controls reduce the risk exposure of a known vulnerability during the remediation period; WAF rules can block specific exploit patterns, network controls can limit who can reach the vulnerable service, and enhanced monitoring provides early warning of exploitation attempts. A is wrong because accepting risk without compensating controls is appropriate only after evaluating and implementing all practical risk reduction options. C is wrong because removing the system from service may not be feasible if it supports business operations; compensating controls allow continued operation with reduced risk. D is wrong because changing risk ratings to avoid alarming stakeholders is dishonest risk management and prevents informed business decisions.