Courseiva
Security Operations →easyMultiple Choice

CS0-003 Security Operations Practice Question

A vulnerability scan report shows a critical vulnerability with a CVSS score of 9.8 on a web server. However, the server is only accessible from internal IP addresses and is protected by a Web Application Firewall (WAF) that blocks the attack vector. Which of the following should the analyst recommend?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Accept the risk due to compensating controls.

Compensating controls like a WAF that effectively blocks the attack reduce the risk. While patching is ideal, the vulnerability may not be immediately exploitable due to the WAF.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Accept the risk due to compensating controls.

    Why this is correct

    Internal-only reachability and a WAF that actively blocks the specific attack vector are legitimate compensating controls that meaningfully reduce exploitability, so documenting a formal risk acceptance with those controls noted, an owner, and a review date is the appropriate response rather than treating the raw CVSS score as the sole driver of urgency.

  • ✗

    Disable the WAF to test the vulnerability.

    Why it's wrong here

    Disabling the WAF to validate the finding would remove the very control that currently mitigates the exposure, needlessly opening a window during which the critical vulnerability becomes exploitable; validation should be performed through safer means such as a controlled test environment, not by degrading production protection.

  • ✗

    Immediately patch the server during business hours.

    Why it's wrong here

    Patching during business hours risks disrupting a production service for a vulnerability that is already substantially mitigated by network isolation and WAF filtering, so forcing an unplanned change into peak hours trades a low residual risk for an unnecessary availability risk that a scheduled maintenance window would avoid.

  • ✗

    Run an uncredentialed scan to confirm the vulnerability.

    Why it's wrong here

    An uncredentialed scan provides an external, unauthenticated view of the host and would not add meaningful confirmation beyond what the original credentialed or authenticated finding already established; it does not address the actual decision point, which is how to handle a vulnerability whose risk is already reduced by existing compensating controls.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.