Courseiva
hardMultiple Select

CS0-003 Practice Question: A vulnerability appears critical but the…

A vulnerability appears critical but the vulnerable feature is disabled. What should the analyst document before downgrading? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that deleting or ignoring a scanner finding is acceptable when a vulnerability is not exploitable, but the correct approach is to document the rationale and obtain approval for a severity downgrade while preserving the finding for audit and compliance purposes.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Approval and rationale for the severity change

When a vulnerability is critical but the vulnerable feature is disabled, the analyst must document the approval and rationale for the severity change to maintain an accurate risk register and audit trail. This ensures that the decision to downgrade is justified, traceable, and compliant with organizational change management policies, preventing arbitrary adjustments that could obscure true risk posture.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Approval and rationale for the severity change

    Why this is correct

    When modifying the severity of a vulnerability, formal approval and a documented rationale are required to maintain compliance and governance. This ensures that any deviation from standard CVSS scores is justified by business context or compensating controls, preventing unauthorized or arbitrary risk acceptance.

  • ✗

    Deletion of the original scanner finding

    Why it's wrong here

    Purging or deleting raw vulnerability scanner findings destroys the historical record and compromises the integrity of the audit trail. Security teams must retain original scan data to track remediation progress and demonstrate compliance during external assessments, even if a finding is determined to be a false positive or mitigated.

  • ✗

    The analyst's personal preference for fewer tickets

    Why it's wrong here

    Vulnerability management decisions must be driven by objective risk metrics, threat intelligence, and technical analysis rather than subjective operational desires. Adjusting severity levels or closing tickets simply to reduce backlog volume introduces unmanaged risk and violates standard security governance frameworks.

  • ✓

    Evidence that the affected feature or code path is not reachable

    Why this is correct

    Demonstrating that a vulnerable component or code path is completely unreachable within the current deployment architecture provides the technical justification needed to downgrade its severity. If an attacker cannot interact with or trigger the vulnerable code, the actual exploitability and associated risk are significantly reduced, justifying a lower priority.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.