🔥 3-day streak
ISACA CRISC — Certified in Risk and Information Systems Control150 / 150
Question 150 of 150
A risk analyst is reviewing the results of a recent vulnerability scan of an internet-facing web application. Two findings are flagged: (1) a critical-severity remote code execution flaw for which no known exploit exists and the affected component is disabled in production, and (2) a medium-severity flaw that is actively being exploited in the wild and is reachable through the application's login page. Management asks the analyst which finding should be prioritized for remediation. What is the analyst's BEST recommendation?
Reviewed for accuracy · Report an issue