mediumMultiple Select
CS0-003 Practice Question: A security analyst is reviewing the results of a…
A security analyst is reviewing the results of a vulnerability scan. The scan identified several critical vulnerabilities on a web server that were previously reported three months ago. Which TWO actions should the analyst take to improve the vulnerability management process?
⚠ Common exam trap
CompTIA often tests the distinction between remediation (fixing the root cause) and mitigation (reducing risk without fixing), leading candidates to overlook that virtual patching is a valid interim action even though it does not permanently resolve the vulnerability.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Increase the frequency of vulnerability scans from quarterly to monthly.
Option B is correct because increasing scan frequency from quarterly to monthly shortens the window in which critical vulnerabilities remain undetected, allowing the organization to identify and remediate issues before they persist for months as in this scenario. Option E is correct because implementing virtual patching or web application firewall (WAF) rules provides a compensating control that mitigates exploitation of known critical vulnerabilities on the web server while permanent remediation is developed and deployed. Option A is incorrect because excluding the web server from future scans would hide real vulnerabilities rather than reduce false positives, undermining the vulnerability management process. Option C is incorrect because automatically closing vulnerabilities after 90 days without remediation creates a false sense of security and does not address the actual risk. Option D is incorrect because scanning during peak business hours can impact production performance and does not improve vulnerability management; scans should typically be scheduled to minimize operational disruption.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Exclude the web server from future scans to reduce the number of false positives.
Why it's wrong here
Excluding a critical asset like a web server from vulnerability scans significantly reduces an organization's security posture by creating blind spots. While it might reduce the number of reported false positives, it critically prevents the detection of legitimate, exploitable vulnerabilities, directly violating the principle of continuous monitoring and comprehensive risk assessment. This practice introduces unacceptable risk by ignoring potential attack vectors.
- ✓
Increase the frequency of vulnerability scans from quarterly to monthly.
Why this is correct
Increasing the frequency of vulnerability scans from quarterly to monthly significantly reduces the window of exposure, minimizing the time an unpatched vulnerability remains undetected and exploitable. This proactive approach ensures more timely identification of newly discovered threats or misconfigurations, allowing for quicker remediation and a stronger overall security posture. It aligns with best practices for continuous security monitoring and risk reduction.
- ✗
Implement a policy to automatically close vulnerabilities after 90 days if no remediation action is taken.
Why it's wrong here
Automatically closing vulnerabilities without actual remediation is a dangerous practice that artificially inflates security metrics and creates a false sense of security. This approach effectively hides known risks, preventing them from being addressed and leaving systems exposed to potential exploitation. Proper vulnerability management requires either remediation, acceptance of risk with documented justification, or implementation of compensating controls, not simply closing the ticket.
- ✗
Schedule the next scan to occur during peak business hours to capture real-world traffic.
Why it's wrong here
Scheduling vulnerability scans during peak business hours is generally discouraged as it can negatively impact system performance and potentially disrupt legitimate user traffic, leading to operational issues. Furthermore, the presence of "real-world traffic" does not inherently affect the detection of critical vulnerabilities, which are typically identified through static analysis or specific probes, regardless of concurrent user activity. Scan frequency and thoroughness are more critical than timing for vulnerability discovery.
- ✓
Implement virtual patching or web application firewall rules to mitigate the vulnerabilities.
Why this is correct
Implementing virtual patching or web application firewall (WAF) rules provides an immediate, compensating control to mitigate identified vulnerabilities, especially when official patches are unavailable or cannot be deployed immediately. These measures act as an interim layer of protection, blocking known attack patterns or exploits at the network edge, thereby reducing the window of exposure and buying time for proper, permanent remediation without disrupting critical services.
Go deeper
Related to this question
Learn chapter
Executive Security Reporting
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Web Application Firewall
A Web Application Firewall (WAF) is a security tool that monitors, filters, and blocks HTTP traffic to and from a web application to protect it from common attacks.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.