Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A vulnerability scan report shows a critical vulnerability with a CVSS score of 10.0. The application team states that the affected service is isolated in a DMZ and has no access to sensitive data. What should the analyst consider?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accept the risk based on compensating controls

Compensating controls like network isolation can reduce the risk even if the vulnerability itself is critical.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Accept the risk based on compensating controls

    Why this is correct

    When a critical vulnerability cannot be immediately patched, security analysts must evaluate the surrounding architecture. Isolating the affected system within a demilitarized zone (DMZ) acts as a compensating control that significantly reduces the threat vector and likelihood of exploitation. Consequently, formally accepting the residual risk is a valid temporary or permanent business decision when these alternative safeguards are active.

  • ✗

    Reclassify the vulnerability as low severity

    Why it's wrong here

    Severity ratings are determined by standardized frameworks like the Common Vulnerability Scoring System (CVSS) based on the intrinsic characteristics of the flaw itself. While compensating controls reduce the overall operational risk, they do not alter the underlying code defect or lower its official severity score. Reclassifying the severity arbitrarily violates vulnerability management standards and masks the true nature of the threat.

  • ✗

    Immediately patch the vulnerability

    Why it's wrong here

    Although applying a patch is the ultimate remediation goal, doing so immediately without testing can cause critical system downtime or compatibility issues. In enterprise environments, change management processes require thorough regression testing before deployment. Given that compensating controls like DMZ isolation are already mitigating the immediate threat, an emergency, untested patch is not the most appropriate immediate action.

  • ✗

    Ignore the finding as a false positive

    Why it's wrong here

    A false positive occurs when a scanner incorrectly identifies a non-existent vulnerability or misinterprets a benign configuration. In this scenario, the vulnerability is genuine and confirmed by the scanner's signature match, meaning it cannot be disregarded. Ignoring a validated critical vulnerability simply because it resides behind a compensating control introduces severe blind spots into the organization's security posture.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.