CS0-003 Vulnerability Management Practice Question
A security analyst is using Qualys to perform a vulnerability scan on a public-facing web server. The scan results show that the server is running an outdated version of Apache HTTP Server with multiple known vulnerabilities. The analyst checks the vendor security advisories and finds that a patch was released three months ago. However, the server is in a staging environment and not yet in production. What should the analyst recommend?
⚠ Common exam trap
CS0-004 often tests the misconception that non-production environments are low risk, when internet-facing staging hosts with known CVEs are prime targets for lateral movement.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Patch the server immediately because it poses a risk to the staging network.
Even in staging, an unpatched public-facing web server with known Apache vulnerabilities is exploitable and can serve as a pivot point into the staging network or be used to attack other environments. Best practice is to patch immediately regardless of environment, because staging often shares credentials, network paths, or data with production. Deferring patching until production migration compounds risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Only patch if the vulnerability is rated critical.
Why it's wrong here
Relying solely on "critical" severity ratings violates standard vulnerability management policies, which typically require remediation of high and medium vulnerabilities as well. Furthermore, attackers frequently chain multiple lower-severity vulnerabilities together to achieve full system compromise, making it dangerous to ignore non-critical findings.
- ✓
Patch the server immediately because it poses a risk to the staging network.
Why this is correct
Staging environments often mirror production configurations and may reside on networks with access to sensitive internal resources or active directory domains. Patching this vulnerability immediately is critical because an attacker could exploit the staging server to establish a foothold and perform lateral movement across the corporate network.
- ✗
Do not patch because the server is not in production.
Why it's wrong here
Leaving a staging server unpatched because it is not in production is a severe security oversight. Staging systems are active network assets that contain real or realistic data, and their compromise can lead to data exfiltration, source code theft, or pivot attacks into production environments.
- ✗
Wait until the server moves to production to patch.
Why it's wrong here
Postponing remediation until production deployment introduces unnecessary risk during the testing lifecycle and increases the likelihood of deploying a known vulnerable configuration. Additionally, patching should be validated in staging first to ensure the fix does not disrupt application functionality before it goes live.
Visual reference
Go deeper
Related to this question
Learn chapter
Infrastructure-as-Code Security Scanning
Key term
Vulnerability scan
A vulnerability scan is an automated process that checks systems, networks, and applications for known security weaknesses or misconfigurations.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.