hardMultiple Choice
CS0-003 Practice Question: A large enterprise uses a vulnerability…
A large enterprise uses a vulnerability management platform that integrates with Active Directory and a configuration management database (CMDB). During a quarterly scan, a critical vulnerability (CVE-2021-44228) is detected on a legacy application server running an end-of-life (EOL) version of Java. The server supports a critical business process and cannot be upgraded or patched because the vendor no longer provides updates. The analyst must reduce the risk to an acceptable level. What is the best approach?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement network segmentation and strict access controls to limit exposure
Network segmentation combined with strict access controls limits the attack surface and potential impact, providing a practical risk reduction when patching is not possible. Removing the server would disrupt business, hotfixes are unavailable, and replacement is a long-term project.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the server from the network until it can be replaced
Why it's wrong here
While disconnecting the affected host completely eliminates the network attack surface, it violates the availability requirement of the CIA triad for a critical business process. This drastic measure causes self-inflicted denial of service and operational disruption, making it an unacceptable immediate response when business continuity must be maintained.
- ✗
Apply a vendor-supplied hotfix to mitigate the vulnerability
Why it's wrong here
Because the asset has reached End-of-Life (EOL) status, the vendor has ceased active support and will not develop, test, or release official hotfixes or patches. Relying on non-existent vendor support is an impossible mitigation strategy, forcing security analysts to look toward compensating controls rather than direct remediation.
- ✗
Replace the server with a newer model that supports patching
Why it's wrong here
Hardware or platform replacement represents a strategic, long-term remediation plan that requires extensive procurement, testing, and migration phases. It fails to address the immediate, active risk posed by the vulnerability today, leaving the enterprise exposed during the lengthy transition period.
- ✓
Implement network segmentation and strict access controls to limit exposure
Why this is correct
When direct patching is impossible due to EOL constraints, implementing compensating controls such as VLAN segmentation, firewall ACLs, and microsegmentation is the industry-standard approach. This restricts lateral movement, isolates the vulnerable system from untrusted zones, and minimizes the overall attack surface while preserving critical business operations.
Go deeper
Related to this question
Learn chapter
Supply Chain Attack Response
Key term
Attack surface
The attack surface is the total sum of all points in a system, network, or application where an unauthorized user can try to enter or extract data.
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.