Courseiva
mediumMultiple Select

CS0-003 Practice Question: A vulnerability management analyst is reviewing…

A vulnerability management analyst is reviewing the results of an authenticated scan. The analyst identifies several medium-severity vulnerabilities that have been present for over a year. Which of the following are the best actions to take? (Choose two.)

⚠ Common exam trap

CompTIA often tests the misconception that old vulnerabilities should automatically be escalated or reclassified, when in fact the first step is always to re-verify the finding with a current scan to avoid wasting resources on false positives or already-remediated issues.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Verify the vulnerabilities are still relevant by re-scanning.

Re-scanning verifies whether the vulnerabilities are still present or have been remediated by other means (e.g., patching, configuration changes). Over a year, the environment may have changed, and the original scan results could be stale. An authenticated scan provides deeper visibility, but a fresh scan is the only way to confirm current relevance before taking further action.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Verify the vulnerabilities are still relevant by re-scanning.

    Why this is correct

    Performing a targeted follow-up scan is the critical first step to validate that the identified vulnerabilities have not already been mitigated by automated patching or configuration changes. This prevents the analyst from wasting organizational resources on false positives or outdated scan data before initiating formal remediation workflows.

  • ✓

    Escalate to the asset owner for remediation.

    Why this is correct

    Assigning responsibility to the designated asset owner is a critical phase of the vulnerability management lifecycle. Once a vulnerability is validated, the asset owner must be notified because they possess the operational authority and context required to apply patches or implement compensating controls.

  • ✗

    Accept the risk if the system is no longer in use.

    Why it's wrong here

    Accepting the risk of an unused system is an inappropriate security posture because inactive systems connected to the network still present an active attack surface. Instead of risk acceptance, the system must be formally decommissioned, isolated, or powered down to eliminate the threat entirely.

  • ✗

    Remove the system from the network.

    Why it's wrong here

    Disconnecting a system from the network is an extreme containment measure reserved for active security incidents or severe, unmitigated zero-day threats. Implementing this action prematurely for routine vulnerability findings disrupts business operations and violates standard operational level agreements.

  • ✗

    Increase the severity rating to high to ensure remediation.

    Why it's wrong here

    Artificially inflating a vulnerability's severity rating distorts the organization's risk prioritization framework and undermines the credibility of the vulnerability management program. Severity ratings should rely on standardized metrics like CVSS scores combined with local environmental factors rather than arbitrary adjustments.

Go deeper

Related to this question

About these practice questions

This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.