Courseiva
hardMultiple Select

CS0-003 Practice Question: An emergency patch may break a revenue-critical…

An emergency patch may break a revenue-critical system. Which actions balance risk and availability? (Choose two.)

⚠ Common exam trap

The CS0-004 exam often tests the misconception that disabling monitoring reduces operational overhead during changes, but the trap here is that it actually increases risk by removing the ability to detect and respond to failures, which is essential for maintaining availability in revenue-critical systems.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Test the patch in a representative staging environment

Testing the emergency patch in a representative staging environment that mirrors the production system's configuration, dependencies, and load allows you to identify potential breaking changes before deployment. This balances risk by validating the patch's impact on revenue-critical systems while maintaining availability, as any failures are contained in the test environment. Option B is correct because applying temporary compensating controls—such as additional monitoring, rate limiting, or failover mechanisms—provides a safety net that reduces the blast radius of a potential patch failure, enabling you to proceed with deployment while preserving system availability.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Test the patch in a representative staging environment

    Why this is correct

    Deploying an emergency patch directly to a revenue-critical production system introduces severe operational risk. Testing the patch in a representative staging environment that mirrors production configurations allows administrators to identify dependency conflicts, performance regressions, or stability issues before deployment, thereby mitigating the risk of costly downtime.

  • ✓

    Apply temporary compensating controls while preparing deployment

    Why this is correct

    When immediate patching is delayed due to testing requirements or potential system instability, implementing temporary compensating controls is necessary. Measures such as tightening firewall rules, deploying specific intrusion prevention system (IPS) signatures, or restricting user access help reduce the attack surface and mitigate vulnerability exposure until the patch can be safely applied.

  • ✗

    Disable monitoring to avoid alerts during the change

    Why it's wrong here

    Disabling monitoring during an emergency change blinds security and operations teams to potential failures or malicious activity occurring during the maintenance window. Instead of disabling alerts entirely, teams should place the affected systems into a scheduled maintenance mode, ensuring that telemetry is still captured for post-incident analysis and real-time troubleshooting.

  • ✗

    Ignore active exploitation until the next annual review

    Why it's wrong here

    Postponing remediation of an actively exploited vulnerability until an annual review violates basic risk management principles and invites a catastrophic breach. Active exploitation demands immediate triage, containment, and mitigation strategies to protect organizational assets, as threat actors will continue to leverage the flaw to compromise the network.

Quick reference

AAA Protocol Comparison

ProtocolPort(s)EncryptionTransportPrimary Use
RADIUS1812 / 1813Password onlyUDPNetwork access control
TACACS+49Full packetTCPDevice administration
Diameter3868Full sessionTCP / SCTPCarrier / mobile networks
802.1X—EAP-basedLayer 2Port-based access control

TACACS+ encrypts the entire packet; RADIUS only encrypts the password field — a key exam distinction.

About these practice questions

One of 701 original CS0-004 practice questions on Courseiva, each with a full explanation and wrong-answer analysis — not exam dumps or protected exam content. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.