Question 1
Q1A security analyst is reviewing external threat intelligence feeds provided by F5 Labs. The research indicates a massive, ongoing campaign utilizing a newly discovered remote code execution (RCE) vulnerability in a popular open-source web framework. The organization relies heavily on this framework for its primary customer portal, but cannot apply the vendor patch for another 30 days due to change freeze constraints. Based on the threat research, what is the MOST immediate potential impact to the organization, and which action should be prioritized?
Show answer & explanation
Correct answer: B
The threat intelligence specifies a Layer 7 (web framework) RCE vulnerability, which directly threatens the application layer with system compromise and data exfiltration. The most effective immediate mitigation, given the inability to patch the backend servers, is to deploy or update BIG-IP ASM/Advanced WAF with the latest attack signatures to virtually patch the vulnerability at the perimeter.