Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

An analyst uses Trivy to scan a container image in a CI/CD pipeline. The scan identifies a vulnerability in an open-source library included in the image. The library is not used by the application code. Which of the following actions should the analyst recommend?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Remove the unused library from the image

Unused components should be removed to reduce attack surface. Patching the library might be unnecessary if not used. Adding a WAF doesn't fix container image vulnerabilities. Accepting risk may be justified but removal is better.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Accept the risk because the library is not used

    Why it's wrong here

    Accepting the risk of an unused but vulnerable library is an insecure practice that unnecessarily inflates the container's attack surface. Even if the library is not actively called by the primary application, it remains present in the filesystem and could be exploited if an attacker gains initial execution context. Removing the component entirely is always preferred over risk acceptance.

  • ✗

    Add a web application firewall (WAF) to protect the container

    Why it's wrong here

    A web application firewall (WAF) operates at the application layer to filter, monitor, and block malicious HTTP/HTTPS traffic. It does not remediate underlying vulnerabilities within the container's local libraries or filesystem. Relying on a WAF as a primary control for container image flaws leaves the system vulnerable to local privilege escalation or non-web-based attack vectors.

  • ✓

    Remove the unused library from the image

    Why this is correct

    Removing the unused library directly eliminates the vulnerability from the container image, adhering to the principle of least utility and minimizing the attack surface. This approach prevents potential exploitation, reduces the overall image size, and streamlines future vulnerability scanning processes. It represents the most secure and efficient remediation strategy for unused dependencies.

  • ✗

    Patch the library to the latest version

    Why it's wrong here

    While patching resolves the specific vulnerability, retaining unused libraries in a container image introduces unnecessary bloat and increases the ongoing maintenance burden. Every additional package in an image represents a potential future vulnerability that must be tracked, scanned, and patched. Eliminating the unused code entirely is superior to patching it.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.