Courseiva
Security Operations →mediumMultiple Choice

CAS-004 Security Operations Practice Question

A vulnerability scanner reports a critical vulnerability with a CVSS base score of 9.8 on a public-facing web server. However, the server has a compensating control: a Web Application Firewall (WAF) that blocks exploit attempts. How should the security team prioritize patching this vulnerability?

⚠ Common exam trap

CAS-005 often tests the misconception that a compensating control like a WAF can replace the need for immediate patching, but the exam expects candidates to recognize that critical vulnerabilities on public-facing systems require urgent remediation regardless of compensating controls.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Immediately patch the vulnerability as soon as possible

The vulnerability has a CVSS base score of 9.8, which is Critical, and the server is public-facing, meaning it is directly exposed to potential attackers. While a WAF provides a compensating control, it is not a foolproof mitigation—WAFs can be bypassed through evasion techniques, misconfigurations, or zero-day exploits. Therefore, the security team should prioritize immediate patching to eliminate the underlying vulnerability, as recommended by risk management frameworks like NIST and CIS. The WAF reduces immediate risk but does not eliminate it, so patching remains urgent.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Schedule patching during the next maintenance window

    Why it's wrong here

    A CVSS 9.8 vulnerability on an internet-facing host warrants emergency patching, not deferral to a routine window; the WAF reduces exploit likelihood but does not remove the flaw, and rule bypasses occur. Maintenance-window scheduling suits medium-severity findings where exposure and impact are contained.

  • ✗

    Defer patching indefinitely since the WAF mitigates the risk

    Why it's wrong here

    Indefinite deferral leaves the vulnerability permanently unpatched; a WAF is a compensating control that reduces but never eliminates exploit risk, and CVSS 9.8 on an internet-facing server requires remediation. Permanent acceptance suits only findings with negligible impact and no feasible fix.

  • ✓

    Immediately patch the vulnerability as soon as possible

    Why this is correct

    A CVSS base score of 9.8 on an internet-facing server warrants immediate remediation; a WAF is a compensating detective or blocking control, not a substitute for patching, since bypasses and rule gaps exist. Delaying based on the WAF leaves the underlying exploitable flaw unaddressed.

  • ✗

    Increase the WAF rule strictness and delay patching

    Why it's wrong here

    Tightening WAF rules does not remediate the underlying flaw; the vulnerable code remains exploitable if rules are bypassed or misconfigured, and CVSS 9.8 demands prompt patching. Rule tuning is appropriate for filtering noisy traffic or virtual-patching while a vendor fix is genuinely unavailable.

About these practice questions

One of 973 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.