Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

During a patch management process, a security analyst is testing a critical security patch in a staging environment. The patch causes a regression in a key business application. Which of the following should the analyst do next?

⚠ Common exam trap

CS0-004 often tests whether candidates confuse 'accepting risk' or 'deploying anyway' with proper remediation — the trap is choosing an action that bypasses the vendor feedback loop or violates change control.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Report the regression to the vendor and wait for a fixed patch

Reporting the regression to the vendor and waiting for a fixed patch is correct because the patch introduces a functional regression in a key business application, meaning it cannot be safely deployed. The proper patch management lifecycle requires that failed patches be documented, communicated to the vendor, and re-tested once a corrected version is available. This preserves both security and business continuity without accepting unmanaged risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✗

    Apply the patch to production but roll back if issues occur

    Why it's wrong here

    Deploying a patch with a known regression to production introduces unnecessary operational risk and violates standard change management protocols. Relying on a rollback plan as a primary strategy for a pre-identified flaw can cause avoidable downtime and potential data corruption. Instead, issues identified during staging must be resolved before any production deployment is authorized.

  • ✗

    Skip the patch and accept the risk

    Why it's wrong here

    Silently skipping the patch and accepting the risk is premature because it leaves the organization vulnerable without attempting remediation. Risk acceptance should only be considered as a last resort after a formal risk assessment and when no vendor-supplied fix or compensating controls are viable. The primary step must always be engaging the vendor to resolve the software defect.

  • ✗

    Deploy the patch to production and monitor for issues

    Why it's wrong here

    Proceeding with deployment while merely monitoring for issues is negligent when testing has already confirmed a regression. This approach exposes critical business systems to known failures and performance degradation, defeating the purpose of the staging and testing phase. Monitoring is a detective control, not a preventive measure for known software bugs.

  • ✓

    Report the regression to the vendor and wait for a fixed patch

    Why this is correct

    The standard operating procedure when finding a regression during patch testing is to document the defect and report it to the software vendor. This allows the vendor to refactor the code and release an updated, stable patch. While waiting, the organization should implement compensating controls to mitigate the underlying vulnerability without breaking production systems.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written and reviewed by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

Last reviewed September 2026 · checked against the official CompTIA exam blueprint

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.