mediumMultiple ChoiceObjective-mapped
CAS-004 Practice Question: During a routine vulnerability scan, a security…
During a routine vulnerability scan, a security engineer discovers that a critical web application is running an outdated version of a third-party library with a known remote code execution (RCE) vulnerability. The application is in production and cannot be taken offline immediately. Which of the following is the BEST immediate action to reduce risk?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a virtual patch using a web application firewall (WAF) to block exploitation patterns.
A WAF rule can block exploitation attempts while a permanent fix is developed. Option A might break functionality. Option C is too slow for immediate risk reduction. Option D might not address the vulnerability entry point.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Patch the library directly in the production environment.
Why it's wrong here
Patching may break the application if not tested; immediate patching is risky.
- ✓
Implement a virtual patch using a web application firewall (WAF) to block exploitation patterns.
Why this is correct
A virtual patch provides temporary protection without affecting application availability.
- ✗
Schedule a maintenance window for the next weekend to apply the vendor's patch.
Why it's wrong here
Delaying exposes the organization to risk for days.
- ✗
Disable the web application until a patch is available.
Why it's wrong here
Severe business impact; not best immediate action if alternative exists.
Go deeper
Related to this question
About these practice questions
One of 968 original CAS-005 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CAS-005 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CAS-005 exam.