mediumMultiple ChoiceObjective-mapped
CS0-003 Practice Question: A security analyst at a financial institution is…
A security analyst at a financial institution is responsible for vulnerability management. The company has a policy that all critical vulnerabilities must be remediated within 72 hours. The weekly vulnerability scan identifies a critical vulnerability on a file server that hosts sensitive customer data. The vulnerability is a remote code execution in the operating system. The server is running a legacy OS that is no longer supported by the vendor. The system owner states that the application on the server cannot be migrated to a newer OS for at least six months. The server cannot be taken offline because it is used by the compliance team for daily audits. Which of the following should the analyst recommend to best address the risk?
⚠ Common exam trap
CompTIA often tests the concept that compensating controls are the appropriate response when patching is impossible and business continuity is critical, tricking candidates into choosing risk acceptance (C) without considering that compensating controls must be implemented first.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement compensating controls such as network segmentation and host-based firewall rules.
When a critical vulnerability cannot be patched due to legacy OS constraints, compensating controls are the best approach to reduce risk. Network segmentation isolates the server from untrusted hosts, and host-based firewall rules restrict inbound/outbound traffic to only necessary ports and IPs, mitigating the remote code execution vector without taking the server offline.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Remove the server from the network immediately.
Why it's wrong here
Removing the server from the network immediately, while seemingly secure, is often impractical and detrimental in a financial institution. Such a drastic action would likely disrupt critical business operations, halt ongoing compliance audits, or prevent essential regulatory reporting, leading to significant financial and legal repercussions. This approach prioritizes security over availability and business continuity without exploring less disruptive mitigation strategies.
- ✓
Implement compensating controls such as network segmentation and host-based firewall rules.
Why this is correct
Implementing compensating controls like network segmentation and host-based firewall rules is the most appropriate immediate action. These controls effectively reduce the attack surface and limit potential exploitation of the vulnerability without disrupting critical services, buying valuable time for a planned migration or upgrade. This strategy aligns with risk management principles by mitigating immediate threats while a long-term solution is prepared and executed.
- ✗
Accept the risk and document the exception.
Why it's wrong here
Accepting the risk and merely documenting an exception is an insufficient response, particularly given a 72-hour remediation policy for vulnerabilities. This approach fails to actively mitigate the identified security weakness, leaving the financial institution exposed to potential breaches, data loss, and severe regulatory penalties. Risk acceptance is typically reserved for low-impact risks or when all other mitigation options are exhausted and formally approved at a high organizational level, which is not the case here.
- ✗
Apply a custom patch developed by the manufacturer.
Why it's wrong here
Applying a custom patch developed by the manufacturer is highly improbable and unrealistic for an end-of-life (EOL) operating system. When an OS reaches EOL, the manufacturer has officially ceased all support, including the development of new security patches or custom fixes. Even if an unofficial patch were somehow created, it would lack vendor backing, potentially introduce new vulnerabilities or system instability, and would not be a reliable, long-term solution for a critical financial system.
Go deeper
Related to this question
Learn chapter
Network Traffic Analysis
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.