Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is evaluating a containerized application for vulnerabilities. The analyst runs Trivy on the container image and finds several high-severity vulnerabilities in the base image. Which of the following is the most effective remediation strategy?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Rebuild the image using a patched base image and redeploy

Rebuilding the container image with a patched base image addresses the root cause by eliminating vulnerable components.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Use a runtime security tool to monitor the container

    Why it's wrong here

    While runtime security tools provide critical visibility into active threats and anomalous behavior within a running container, they function strictly as detective controls. They do not remediate the underlying vulnerabilities present in the container's libraries or application code, leaving the attack surface fully exposed to potential exploitation.

  • ✗

    Apply a host-based firewall to block exploitation attempts

    Why it's wrong here

    Implementing a host-based firewall acts as a compensating network control that can restrict unauthorized traffic, but it fails to address the root cause of the vulnerability inside the containerized application. Attackers can often bypass network-level filters using legitimate, permitted communication channels to exploit application-layer flaws.

  • ✓

    Rebuild the image using a patched base image and redeploy

    Why this is correct

    Containers are designed to be immutable, meaning that patching a running instance directly is a major operational anti-pattern. The correct remediation workflow requires updating the Dockerfile or base image to a secure version, rebuilding the container image, and redeploying it to eliminate the vulnerabilities at their source.

  • ✗

    Disable the container until a patch is available

    Why it's wrong here

    Disabling or shutting down the container is an extreme containment measure that causes immediate service disruption and does not actually resolve the underlying security flaws. Once the container is spun back up, the same vulnerabilities will persist until the underlying image is updated, rebuilt, and redeployed.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.