CS0-003 Security Operations Practice Question
A vulnerability scan report shows a critical vulnerability with a CVSS score of 10.0. The application team states that the affected service is isolated in a DMZ and has no access to sensitive data. What should the analyst consider?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Accept the risk based on compensating controls
Compensating controls like network isolation can reduce the risk even if the vulnerability itself is critical.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Accept the risk based on compensating controls
Why this is correct
When a critical vulnerability cannot be immediately patched, security analysts must evaluate the surrounding architecture. Isolating the affected system within a demilitarized zone (DMZ) acts as a compensating control that significantly reduces the threat vector and likelihood of exploitation. Consequently, formally accepting the residual risk is a valid temporary or permanent business decision when these alternative safeguards are active.
- ✗
Reclassify the vulnerability as low severity
Why it's wrong here
Severity ratings are determined by standardized frameworks like the Common Vulnerability Scoring System (CVSS) based on the intrinsic characteristics of the flaw itself. While compensating controls reduce the overall operational risk, they do not alter the underlying code defect or lower its official severity score. Reclassifying the severity arbitrarily violates vulnerability management standards and masks the true nature of the threat.
- ✗
Immediately patch the vulnerability
Why it's wrong here
Although applying a patch is the ultimate remediation goal, doing so immediately without testing can cause critical system downtime or compatibility issues. In enterprise environments, change management processes require thorough regression testing before deployment. Given that compensating controls like DMZ isolation are already mitigating the immediate threat, an emergency, untested patch is not the most appropriate immediate action.
- ✗
Ignore the finding as a false positive
Why it's wrong here
A false positive occurs when a scanner incorrectly identifies a non-existent vulnerability or misinterprets a benign configuration. In this scenario, the vulnerability is genuine and confirmed by the scanner's signature match, meaning it cannot be disregarded. Ignoring a validated critical vulnerability simply because it resides behind a compensating control introduces severe blind spots into the organization's security posture.
Go deeper
Related to this question
Learn chapter
Cloud Vulnerability Management
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.