hardMultiple Select
CS0-003 Practice Question: A vulnerability appears critical but the…
A vulnerability appears critical but the vulnerable feature is disabled. What should the analyst document before downgrading? (Choose two.)
⚠ Common exam trap
The CS0-004 exam often tests the misconception that deleting or ignoring a scanner finding is acceptable when a vulnerability is not exploitable, but the correct approach is to document the rationale and obtain approval for a severity downgrade while preserving the finding for audit and compliance purposes.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Approval and rationale for the severity change
When a vulnerability is critical but the vulnerable feature is disabled, the analyst must document the approval and rationale for the severity change to maintain an accurate risk register and audit trail. This ensures that the decision to downgrade is justified, traceable, and compliant with organizational change management policies, preventing arbitrary adjustments that could obscure true risk posture.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Approval and rationale for the severity change
Why this is correct
When modifying the severity of a vulnerability, formal approval and a documented rationale are required to maintain compliance and governance. This ensures that any deviation from standard CVSS scores is justified by business context or compensating controls, preventing unauthorized or arbitrary risk acceptance.
- ✗
Deletion of the original scanner finding
Why it's wrong here
Purging or deleting raw vulnerability scanner findings destroys the historical record and compromises the integrity of the audit trail. Security teams must retain original scan data to track remediation progress and demonstrate compliance during external assessments, even if a finding is determined to be a false positive or mitigated.
- ✗
The analyst's personal preference for fewer tickets
Why it's wrong here
Vulnerability management decisions must be driven by objective risk metrics, threat intelligence, and technical analysis rather than subjective operational desires. Adjusting severity levels or closing tickets simply to reduce backlog volume introduces unmanaged risk and violates standard security governance frameworks.
- ✓
Evidence that the affected feature or code path is not reachable
Why this is correct
Demonstrating that a vulnerable component or code path is completely unreachable within the current deployment architecture provides the technical justification needed to downgrade its severity. If an attacker cannot interact with or trigger the vulnerable code, the actual exploitability and associated risk are significantly reduced, justifying a lower priority.
Go deeper
Related to this question
Learn chapter
Nessus Vulnerability Scanner
Key term
Audit
An audit is a systematic, independent review of IT systems, processes, and controls to verify compliance with policies, standards, and regulations.
Key term
Audit trail
An audit trail is a chronological record of events, changes, or activities in a system that provides evidence of who did what, when, and from where.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.