Courseiva
easyMultiple Choice

CS0-003 Practice Question: A penetration testing team has completed an…

A penetration testing team has completed an internal assessment and provided a report with several high-risk findings. One finding indicates that a web application is vulnerable to SQL injection. The application is used by external customers to submit orders. The development team has reviewed the finding and states that it will take three weeks to fix the code and deploy a patch. The security operations center (SOC) has observed increased scanning activity targeting the application's IP address from external sources. The company's risk tolerance for web application vulnerabilities is low. Which of the following should the analyst recommend as the immediate next step?

⚠ Common exam trap

A common mix-up: candidates choose to disable the application (Option C) thinking it is the safest approach, but the CompTIA CySA+ exam emphasizes the balance between security and business continuity, where a compensating control like a WAF is the preferred immediate step when a patch is not immediately available.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Deploy a web application firewall (WAF) with rules to block SQL injection attempts.

Deploying a WAF with rules to block SQL injection attempts is the immediate next step because it provides a virtual patch that mitigates the vulnerability while the development team works on the permanent code fix. Given the low risk tolerance and active external scanning, this reduces the attack surface without taking the application offline, which would disrupt customer order submissions.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Deploy a web application firewall (WAF) with rules to block SQL injection attempts.

    Why this is correct

    Deploying a WAF provides immediate virtual patching at the HTTP layer, inspecting request payloads for SQL injection signatures and blocking them before they reach the vulnerable application. This satisfies the low risk tolerance and active external scanning constraint, buying three weeks until the code fix is deployed.

  • ✗

    Increase logging and monitoring for SQL injection attempts.

    Why it's wrong here

    Logging and monitoring only detect exploitation attempts; they do not block them, leaving the vulnerable order-submission application exposed to the active external scanning. A compensating control such as a web application firewall with SQL injection rules is required while the three-week code fix is pending.

  • ✗

    Disable the web application until the patch is deployed.

    Why it's wrong here

    Taking the order-submission application offline halts legitimate external customer orders, an availability impact disproportionate to the threat. A compensating control such as a web application firewall with SQL injection rules mitigates the vulnerability while the three-week patch is developed.

  • ✗

    Request the development team to expedite the patch within one week.

    Why it's wrong here

    Compressing the patch timeline to one week still leaves the externally reachable application exploitable during that window, and it does not address the scanning already observed. An immediate compensating control, such as a web application firewall filtering SQL injection, is needed now.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.