CAS-004 Security Operations Practice Question
A vulnerability scanner reports a critical vulnerability with a CVSS base score of 9.8 on a public-facing web server. However, the server has a compensating control: a Web Application Firewall (WAF) that blocks exploit attempts. How should the security team prioritize patching this vulnerability?
⚠ Common exam trap
CAS-005 often tests the misconception that a compensating control like a WAF can replace the need for immediate patching, but the exam expects candidates to recognize that critical vulnerabilities on public-facing systems require urgent remediation regardless of compensating controls.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Immediately patch the vulnerability as soon as possible
The vulnerability has a CVSS base score of 9.8, which is Critical, and the server is public-facing, meaning it is directly exposed to potential attackers. While a WAF provides a compensating control, it is not a foolproof mitigation—WAFs can be bypassed through evasion techniques, misconfigurations, or zero-day exploits. Therefore, the security team should prioritize immediate patching to eliminate the underlying vulnerability, as recommended by risk management frameworks like NIST and CIS. The WAF reduces immediate risk but does not eliminate it, so patching remains urgent.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Schedule patching during the next maintenance window
Why it's wrong here
A CVSS 9.8 vulnerability on an internet-facing host warrants emergency patching, not deferral to a routine window; the WAF reduces exploit likelihood but does not remove the flaw, and rule bypasses occur. Maintenance-window scheduling suits medium-severity findings where exposure and impact are contained.
- ✗
Defer patching indefinitely since the WAF mitigates the risk
Why it's wrong here
Indefinite deferral leaves the vulnerability permanently unpatched; a WAF is a compensating control that reduces but never eliminates exploit risk, and CVSS 9.8 on an internet-facing server requires remediation. Permanent acceptance suits only findings with negligible impact and no feasible fix.
- ✓
Immediately patch the vulnerability as soon as possible
Why this is correct
A CVSS base score of 9.8 on an internet-facing server warrants immediate remediation; a WAF is a compensating detective or blocking control, not a substitute for patching, since bypasses and rule gaps exist. Delaying based on the WAF leaves the underlying exploitable flaw unaddressed.
- ✗
Increase the WAF rule strictness and delay patching
Why it's wrong here
Tightening WAF rules does not remediate the underlying flaw; the vulnerable code remains exploitable if rules are bypassed or misconfigured, and CVSS 9.8 demands prompt patching. Rule tuning is appropriate for filtering noisy traffic or virtual-patching while a vendor fix is genuinely unavailable.
Go deeper
Related to this question
About these practice questions
One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.