An organization suspects a persistent threat from a cybercriminal. They hire an ethical hacker, John, to evaluate their system security. John identifies several vulnerabilities and advises the organization on preventive measures. However, the organization has limited resources and opts to fix only the most severe vulnerability. Subsequently, a data breach occurs exploiting a different vulnerability. Which of the following statements best describes this scenario?
- AThe organization is at fault because it did not fix all identified vulnerabilities. (correct answer)
- BBoth the organization and John share responsibility because they did not adequately manage the vulnerabilities.
- CJohn is at fault because he did not emphasize the necessity of patching all vulnerabilities.
- DThe organization is not at fault because they used their resources as per their understanding.
Reveal answer & explanationHide answer
The correct answer is A. Option A: The organization is at fault because it did not fix all identified vulnerabilities. This option keeps traffic private / properly secured as required.