CS0-003 Vulnerability Management Practice Question
During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch causes a regression in a key business application. Which of the following should the analyst do next?
⚠ Common exam trap
CS0-004 often tests whether candidates confuse 'accepting risk' or 'deploying anyway' with proper remediation — the trap is choosing an action that bypasses the vendor feedback loop or violates change control.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Report the regression to the vendor and wait for a fixed patch
Reporting the regression to the vendor and waiting for a fixed patch is correct because the patch introduces a functional regression in a key business application, meaning it cannot be safely deployed. The proper patch management lifecycle requires that failed patches be documented, communicated to the vendor, and re-tested once a corrected version is available. This preserves both security and business continuity without accepting unmanaged risk.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Apply the patch to production but roll back if issues occur
Why it's wrong here
Deploying a patch with a known regression to production introduces unnecessary operational risk and violates standard change management protocols. Relying on a rollback plan as a primary strategy for a pre-identified flaw can cause avoidable downtime and potential data corruption. Instead, issues identified during staging must be resolved before any production deployment is authorized.
- ✗
Skip the patch and accept the risk
Why it's wrong here
Silently skipping the patch and accepting the risk is premature because it leaves the organization vulnerable without attempting remediation. Risk acceptance should only be considered as a last resort after a formal risk assessment and when no vendor-supplied fix or compensating controls are viable. The primary step must always be engaging the vendor to resolve the software defect.
- ✗
Deploy the patch to production and monitor for issues
Why it's wrong here
Proceeding with deployment while merely monitoring for issues is negligent when testing has already confirmed a regression. This approach exposes critical business systems to known failures and performance degradation, defeating the purpose of the staging and testing phase. Monitoring is a detective control, not a preventive measure for known software bugs.
- ✓
Report the regression to the vendor and wait for a fixed patch
Why this is correct
The standard operating procedure when finding a regression during patch testing is to document the defect and report it to the software vendor. This allows the vendor to refactor the code and release an updated, stable patch. While waiting, the organization should implement compensating controls to mitigate the underlying vulnerability without breaking production systems.
Go deeper
Related to this question
Learn chapter
SOC Tier 1, Tier 2, and Tier 3 Analyst Roles
Key term
Quality update policy
A quality update policy is a set of rules and schedules that IT administrators use to control which Windows updates are deployed to devices to ensure stability, security, and compatibility.
Key term
Security
Security in IT is the practice of protecting systems, networks, and data from unauthorized access, damage, or theft.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written and reviewed by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
Last reviewed September 2026 · checked against the official CompTIA exam blueprint
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.