Several unrelated incidents trace back to misconfigured firewalls deployed by different teams. A risk practitioner wants the vulnerability analysis to prevent recurrence rather than repeatedly patch symptoms. Which step is the most useful next action?
- AReconfigure every affected firewall immediately and close each incident as a separately resolved finding
- BPerform root cause analysis to determine why the misconfigurations keep arising across the separate teams Correct
- CRaise the residual risk rating for the firewall estate and escalate the revised figure to senior leadership
- DCommission an external penetration test of the perimeter to confirm the firewalls remain exploitable today
Why A is wrong: Fixing each device feels decisive and fast, but it treats symptoms in isolation and leaves the systemic cause intact, so similar misconfigurations will recur across the teams.
Why B is correct: Root cause analysis targets the systemic source feeding repeated misconfigurations, so addressing it prevents recurrence rather than fixing each firewall as an isolated symptom.
Why C is wrong: Re-rating residual risk records severity for governance, yet it does not explain why the misconfigurations happen, so it cannot prevent the pattern from repeating.
Why D is wrong: A penetration test can confirm exploitability, but it rediscovers symptoms already known from incidents and still leaves the recurring underlying cause unaddressed.