Courseiva
Vulnerability Management →hardMultiple Choice

CS0-003 Vulnerability Management Practice Question

A security analyst is reviewing the results of a container image scan using Trivy. The scan reports a critical vulnerability in a base image layer. The development team states that the vulnerability is not exploitable because the affected library is not used in the application. According to vulnerability management best practices, what should the analyst do?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Request that the development team remove the unused library and rebuild the image.

Even if the library is not used, it is best practice to rebuild the image with a patched base image to eliminate the vulnerability and ensure compliance.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the risk and close the finding.

    Why it's wrong here

    Accepting the risk and closing the finding is inappropriate because the vulnerability exists within an unused library that can easily be removed. Risk acceptance should only be reserved for situations where remediation is technically impossible, excessively costly, or introduces significant operational disruption, none of which apply to removing dead code from a container image.

  • ✓

    Request that the development team remove the unused library and rebuild the image.

    Why this is correct

    The most effective remediation strategy for container security is to minimize the attack surface by practicing container hygiene. Requesting that the development team remove the unnecessary library and rebuild the base image permanently eliminates the vulnerability at the source, preventing it from being deployed into production environments.

  • ✗

    Ignore the finding since it is not exploitable.

    Why it's wrong here

    Ignoring the finding based on a temporary lack of exploitability is a dangerous practice that violates fundamental security compliance frameworks. Even if a vulnerability is not currently exploitable in the container's current configuration, subsequent code updates or configuration changes could inadvertently expose the vulnerable library to execution, creating a latent security risk.

  • ✗

    Apply a compensating control at the network level to block exploitation.

    Why it's wrong here

    While network-level compensating controls like Web Application Firewalls (WAFs) or microsegmentation can mitigate certain threats, they do not address the root cause of the vulnerability within the container image. Relying on network controls introduces unnecessary operational complexity, increases the monitoring burden, and leaves the container vulnerable to internal lateral movement or non-network attack vectors.

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.