Courseiva
Vulnerability ManagementhardMultiple ChoiceObjective-mapped

CS0-003 Vulnerability Management Practice Question

A security team discovers a critical vulnerability in a widely used software component. The vulnerability has a CVSS score of 9.0, but there is no known exploit or patch available yet. However, the software vendor has released a workaround. According to the vulnerability management lifecycle, which action should the team prioritize first?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Apply the workaround as a compensating control

Since no patch is available, the team should apply compensating controls to mitigate the risk. Remediation typically involves patching, but if not possible, compensating controls are the next best step.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Wait for the vendor to release a patch before taking any action

    Why it's wrong here

    Waiting for a vendor patch leaves the critical vulnerability unaddressed, significantly increasing the organization's exposure to potential exploitation. This passive approach prolongs the risk window, allowing attackers more time to discover and leverage the flaw. Proactive measures, such as implementing compensating controls, are essential to mitigate immediate threats and reduce the attack surface while awaiting a permanent fix.

  • Remove the affected component from all systems immediately

    Why it's wrong here

    Immediately removing a critical component from all systems is often an impractical and highly disruptive measure that can severely impact business operations and service availability. While it eliminates the vulnerability, the operational cost and potential for service outages typically outweigh the benefits as a primary response. Feasible compensating controls are generally preferred to maintain functionality while reducing risk.

  • Increase monitoring of the affected systems but take no other action

    Why it's wrong here

    Merely increasing monitoring of affected systems without implementing active mitigation steps is insufficient for addressing a critical vulnerability. Enhanced monitoring can help detect exploitation attempts, but it does not prevent them or reduce the underlying risk posed by the unpatched flaw. Active measures, such as applying a workaround or isolating the system, are necessary to actually reduce the attack surface and potential impact.

  • Apply the workaround as a compensating control

    Why this is correct

    Applying a workaround as a compensating control is the most appropriate immediate action when a critical vulnerability is discovered and a vendor patch is not yet available. A compensating control is an alternative security measure that reduces the risk to an acceptable level until a permanent solution can be implemented. This approach effectively mitigates the immediate threat without causing undue operational disruption, balancing security with business continuity.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.