Courseiva
Vulnerability ManagementmediumMultiple ChoiceObjective-mapped

CS0-003 Vulnerability Management Practice Question

A vulnerability management team is evaluating whether to apply a patch immediately or implement a compensating control. The patch is for a vulnerability in a legacy system that cannot be taken offline during business hours. The compensating control would involve restricting network access to the system. Which decision is MOST appropriate?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Implement a compensating control and schedule patching during a maintenance window

If the system cannot be patched immediately, implementing a compensating control (network restriction) reduces risk while waiting for a maintenance window.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Ignore the vulnerability since it affects a legacy system

    Why it's wrong here

    Legacy systems often run unsupported operating systems or applications that no longer receive vendor security updates, making them a high-value target for attackers. Ignoring a known vulnerability on such a system leaves the organization exposed to potential data breaches, especially if the system is accessible from the network or connected to other critical assets. Even if the system is isolated, it can be compromised via lateral movement from another infected host. Therefore, it is unacceptable to simply ignore the vulnerability.

  • Remove the system from the network

    Why it's wrong here

    Removing the system from the network is an overly drastic action that can severely impact business processes, particularly if the system provides critical services or data that other applications depend on. A more proportionate response is to apply compensating controls, such as network segmentation, host-based firewalls, or advanced access controls, to mitigate the immediate risk while a patch is prepared. Full isolation might be reserved for situations where the vulnerability is actively exploited and no other mitigation exists, but it should not be the default decision due to the potential for significant operational disruption.

  • Implement a compensating control and schedule patching during a maintenance window

    Why this is correct

    This approach aligns with best-practice vulnerability management by balancing the need for security against operational availability. A compensating control, such as an internal network access control list (ACL) or an updated intrusion prevention system (IPS) signature, reduces the likelihood or impact of exploitation until the patch can be installed during a scheduled maintenance window. This ensures that the system remains functional and that the patch is tested and deployed in a controlled manner, minimizing downtime and the risk of unexpected failures. It is the correct decision because it addresses the vulnerability without disproportionate disruption to the business.

  • Apply the patch immediately despite the outage risk

    Why it's wrong here

    While time is critical for high-severity vulnerabilities, applying a patch immediately without a proper change window can cause service outages that are equally damaging to the business. The decision to patch should consider the exploitability of the vulnerability, the system's role, and the potential impact of downtime on service-level agreements (SLAs). If the system is not directly exposed to the internet or has other mitigations in place, the risk of waiting for a maintenance window is often lower than the risk of an unplanned outage. Therefore, immediate patching is not always the best approach, especially when it could lead to availability failures that affect critical operations.

About these practice questions

One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.