sratakhin wrote: » I think both answers are good.
JDMurray wrote: » From the two exam items given, the correct choices would be either C & D or D & C. They both can't be D.
the_hutch wrote: » You don't implement good security policy or awareness training to protect your organization from zero-day attacks. Zero day attacks by definition have no effective countermeasure. By definition, the only risk management option in this case is risk acceptance. There is no way to effectivley mitigate them
ptilsen wrote: » The second question is better-phrased in this regard because it focuses on mitigation against the attack, rather than "defense". It's an important distinction, because as you said, a zero-day exploit it cannot be defended against or prevented, but as I am saying its effects can still be mitigated.
the_hutch wrote: » I kinda think both of those questions are kinda bullshit... You don't implement good security policy or awareness training to protect your organization from zero-day attacks.