easyMultiple Choice
CS0-003 Practice Question: A company has a policy to remediate…
A company has a policy to remediate vulnerabilities within 30 days. A critical vulnerability is discovered on a database server. The patch requires a reboot, and the database cannot be taken offline during business hours. Which of the following is the BEST approach?
⚠ Common exam trap
CompTIA often tests the balance between security and operations. Students often think that critical vulnerabilities must be patched immediately (even if it violates SLAs) or that compensating controls are the first choice. However, if a maintenance window is available outside of business hours, scheduling the patch is the correct and standard procedure to achieve actual remediation.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule the patch during the next maintenance window
Since the database cannot be taken offline during business hours, the standard and best practice is to schedule the installation and reboot during the next scheduled maintenance window (which occurs outside of business hours). This allows the vulnerability to be fully remediated (patched) within the 30-day policy limit without violating operational SLAs. Compensating controls are typically reserved for situations where a patch cannot be applied at all or must be delayed significantly beyond policy limits.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Implement a compensating control
Why it's wrong here
When direct patching is not immediately possible due to operational constraints or testing requirements, implementing a compensating control is the most appropriate action. This involves deploying alternative security measures, such as network segmentation, intrusion prevention system (IPS) rules, or enhanced monitoring, to reduce the exploitability or impact of the vulnerability. These controls effectively lower the immediate risk, allowing the organization to adhere to the 30-day remediation policy while planning for the permanent patch deployment.
- ✗
Apply a hotfix without reboot
Why it's wrong here
Applying a hotfix without a system reboot is often insufficient for fully addressing a vulnerability, as many patches require a complete restart to properly load new kernel modules, libraries, or system services. This approach risks leaving the vulnerability partially exploitable or introducing system instability due to mismatched components. Consequently, it fails to reliably remediate the vulnerability within the policy timeframe and may create new operational issues.
- ✓
Schedule the patch during the next maintenance window
Why this is correct
Scheduling the patch for the next maintenance window, especially if it's more than 30 days away, directly violates the company's established remediation policy. This approach leaves the vulnerability unaddressed and the system exposed for an extended period, significantly increasing the risk of exploitation. It prioritizes operational convenience over security policy adherence and immediate risk mitigation.
- ✗
Extend the remediation deadline
Why it's wrong here
Simply extending the remediation deadline is an administrative action that does not address the underlying technical vulnerability or reduce the associated risk. This approach constitutes a direct violation of the company's security policy, as it merely postpones compliance without implementing any actual security measure. It demonstrates a failure to prioritize security and can lead to a culture of non-compliance with critical vulnerability management standards.
Go deeper
Related to this question
Learn chapter
Web Application Vulnerability Scanning
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Policy
A policy is a set of rules or guidelines that defines how an organization manages, secures, and operates its IT systems and services.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.