Courseiva
mediumMultiple Choice

CS0-003 Practice Question: Ensure that all servers are patched within 30…

A company wants to ensure that all servers are patched within 30 days of a critical patch release. The security team must verify compliance without causing downtime. Which of the following is the best approach?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Conduct automated vulnerability scanning of the server IP ranges.

Automated vulnerability scanning provides a non-intrusive method to check patch levels without affecting system availability. Manual checks are inefficient; agent-based solutions are effective but may introduce overhead; network segmentation does not verify patch compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Perform manual patch verification on a rotating schedule.

    Why it's wrong here

    A manual rotating schedule depends on staff availability and consistency, so it inevitably leaves gaps between checks where a server could sit unpatched past the 30-day SLA without anyone noticing, and it scales poorly across a large enterprise server fleet.

  • ✓

    Conduct automated vulnerability scanning of the server IP ranges.

    Why this is correct

    Scanning server IP ranges from the network requires no software installation on the hosts themselves, so it verifies patch compliance without touching running processes or requiring a reboot, satisfying the requirement to confirm remediation status without introducing downtime risk.

  • ✗

    Deploy an agent-based patch management solution to all servers.

    Why it's wrong here

    Rolling out an agent to every server means installing and maintaining new software on production systems, which introduces its own change-management risk, resource consumption, and potential for service interruption during deployment, working against the stated goal of avoiding downtime.

  • ✗

    Implement network segmentation to isolate unpatched servers.

    Why it's wrong here

    Segmenting unpatched servers onto an isolated network reduces their exposure to lateral attack but provides no mechanism to actually detect which servers are missing the critical patch, so it fails to answer the compliance-verification requirement the team was tasked with.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.