CS0-003 Vulnerability Management Practice Question
A security team discovers a critical vulnerability in a widely used software component. The vulnerability has a CVSS score of 9.0, but there is no known exploit or patch available yet. However, the software vendor has released a workaround. According to the vulnerability management lifecycle, which action should the team prioritize first?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply the workaround as a compensating control
Since no patch is available, the team should apply compensating controls to mitigate the risk. Remediation typically involves patching, but if not possible, compensating controls are the next best step.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Wait for the vendor to release a patch before taking any action
Why it's wrong here
Waiting for a vendor patch leaves the critical vulnerability unaddressed, significantly increasing the organization's exposure to potential exploitation. This passive approach prolongs the risk window, allowing attackers more time to discover and leverage the flaw. Proactive measures, such as implementing compensating controls, are essential to mitigate immediate threats and reduce the attack surface while awaiting a permanent fix.
- ✗
Remove the affected component from all systems immediately
Why it's wrong here
Immediately removing a critical component from all systems is often an impractical and highly disruptive measure that can severely impact business operations and service availability. While it eliminates the vulnerability, the operational cost and potential for service outages typically outweigh the benefits as a primary response. Feasible compensating controls are generally preferred to maintain functionality while reducing risk.
- ✗
Increase monitoring of the affected systems but take no other action
Why it's wrong here
Merely increasing monitoring of affected systems without implementing active mitigation steps is insufficient for addressing a critical vulnerability. Enhanced monitoring can help detect exploitation attempts, but it does not prevent them or reduce the underlying risk posed by the unpatched flaw. Active measures, such as applying a workaround or isolating the system, are necessary to actually reduce the attack surface and potential impact.
- ✓
Apply the workaround as a compensating control
Why this is correct
Applying a workaround as a compensating control is the most appropriate immediate action when a critical vulnerability is discovered and a vendor patch is not yet available. A compensating control is an alternative security measure that reduces the risk to an acceptable level until a permanent solution can be implemented. This approach effectively mitigates the immediate threat without causing undue operational disruption, balancing security with business continuity.
Go deeper
Related to this question
Learn chapter
Vulnerability Scanning Techniques
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.