CS0-003 Vulnerability Management Practice Question
A vulnerability management team is evaluating whether to apply a patch immediately or implement a compensating control. The patch is for a vulnerability in a legacy system that cannot be taken offline during business hours. The compensating control would involve restricting network access to the system. Which decision is MOST appropriate?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Implement a compensating control and schedule patching during a maintenance window
If the system cannot be patched immediately, implementing a compensating control (network restriction) reduces risk while waiting for a maintenance window.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Ignore the vulnerability since it affects a legacy system
Why it's wrong here
Legacy systems often run unsupported operating systems or applications that no longer receive vendor security updates, making them a high-value target for attackers. Ignoring a known vulnerability on such a system leaves the organization exposed to potential data breaches, especially if the system is accessible from the network or connected to other critical assets. Even if the system is isolated, it can be compromised via lateral movement from another infected host. Therefore, it is unacceptable to simply ignore the vulnerability.
- ✗
Remove the system from the network
Why it's wrong here
Removing the system from the network is an overly drastic action that can severely impact business processes, particularly if the system provides critical services or data that other applications depend on. A more proportionate response is to apply compensating controls, such as network segmentation, host-based firewalls, or advanced access controls, to mitigate the immediate risk while a patch is prepared. Full isolation might be reserved for situations where the vulnerability is actively exploited and no other mitigation exists, but it should not be the default decision due to the potential for significant operational disruption.
- ✓
Implement a compensating control and schedule patching during a maintenance window
Why this is correct
This approach aligns with best-practice vulnerability management by balancing the need for security against operational availability. A compensating control, such as an internal network access control list (ACL) or an updated intrusion prevention system (IPS) signature, reduces the likelihood or impact of exploitation until the patch can be installed during a scheduled maintenance window. This ensures that the system remains functional and that the patch is tested and deployed in a controlled manner, minimizing downtime and the risk of unexpected failures. It is the correct decision because it addresses the vulnerability without disproportionate disruption to the business.
- ✗
Apply the patch immediately despite the outage risk
Why it's wrong here
While time is critical for high-severity vulnerabilities, applying a patch immediately without a proper change window can cause service outages that are equally damaging to the business. The decision to patch should consider the exploitability of the vulnerability, the system's role, and the potential impact of downtime on service-level agreements (SLAs). If the system is not directly exposed to the internet or has other mitigations in place, the risk of waiting for a maintenance window is often lower than the risk of an unplanned outage. Therefore, immediate patching is not always the best approach, especially when it could lead to availability failures that affect critical operations.
Go deeper
Related to this question
Learn chapter
Network Traffic Analysis
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Vulnerability management
Vulnerability management is the continuous process of identifying, classifying, prioritizing, and remediating security weaknesses in an organization's IT environment.
About these practice questions
One of 236 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.