A critical CVE on the city's VPN concentrator now has public exploit code circulating. Which mitigation should be prioritized first for that vulnerability?
Select an answer to reveal the explanation.
Short Explanation
When exploit code is already in the wild, patch the hole—yesterday if you can. The VPN box is the priority patient; waiting for a hardware refresh or reimaging laptops does not close that CVE.
Full Explanation
Timely patching of critical vulnerabilities—especially internet-facing or remote-access appliances with public exploits—is a primary mitigation. Delaying for annual refresh cycles, unrelated endpoint projects, or increasing exposure of admin interfaces leaves the known flaw available to attackers.