CS0-003 Vulnerability Management Practice Question
An organization uses Qualys for vulnerability scanning. After a scan, the security team identifies a vulnerability with an EPSS score of 0.95 and that appears in the CISA KEV catalog. However, the affected asset is a non-critical development server with no internet access. According to the vulnerability lifecycle, what should be the analyst's NEXT action?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the finding and schedule remediation during the next regular maintenance window.
Despite high EPSS and KEV listing, the asset's low business context (non-critical, no internet access) reduces risk; the analyst should prioritize based on business context, likely scheduling remediation with lower urgency.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply a compensating control, such as a firewall rule blocking access to the server.
Why it's wrong here
While compensating controls like firewall blocks are useful for mitigating high-risk exposures, they are unnecessary and introduce operational overhead for an internal, non-critical asset. The standard vulnerability management lifecycle dictates that after analyzing the business context, the finding should first be prioritized and scheduled rather than immediately applying disruptive network-level restrictions.
- ✗
Escalate the vulnerability to management for emergency patching.
Why it's wrong here
Escalating to management for out-of-band or emergency patching bypasses standard change management and should be reserved for critical assets or active threats. Because this server lacks internet exposure and holds low business value, initiating an emergency response would waste valuable security resources and disrupt normal operations.
- ✓
Document the finding and schedule remediation during the next regular maintenance window.
Why this is correct
Incorporating both vulnerability severity and business context is fundamental to risk-based vulnerability management. Since the asset is non-critical and isolated from the internet, the overall risk is low despite a high EPSS score, making it appropriate to document the vulnerability and remediate it during the next scheduled maintenance window without disrupting business operations.
- ✗
Immediately patch the server within 48 hours due to the high EPSS score.
Why it's wrong here
Relying solely on the Exploit Prediction Scoring System (EPSS) score ignores critical environmental factors like asset criticality and network exposure. An immediate 48-hour patching SLA is an inefficient allocation of resources for an isolated, non-critical system, as risk is a function of both threat likelihood and business impact.
Go deeper
Related to this question
Learn chapter
Zero-Day Vulnerability Response
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.