Courseiva
Vulnerability Management →mediumMultiple Choice

CS0-003 Vulnerability Management Practice Question

During a vulnerability assessment, a security analyst discovers a critical vulnerability affecting a legacy application that cannot be patched due to vendor end-of-life status. Which of the following is the BEST next step?

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Document the risk and implement compensating controls

When a patch is not available, implementing compensating controls is the best approach to mitigate risk. This may include network segmentation, access controls, or additional monitoring.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Document the risk and implement compensating controls

    Why this is correct

    When a legacy application cannot be patched, the vulnerability management lifecycle dictates that the risk must be formally accepted and documented in the risk register. To mitigate the exposure while maintaining business operations, the organization must implement compensating controls, such as network segmentation or strict access control lists, to reduce the likelihood or impact of exploitation.

  • ✗

    Remove the legacy application from the network immediately

    Why it's wrong here

    Removing the legacy application immediately would cause an operational outage, violating the requirement to maintain business continuity while the vulnerability is addressed. This action is tempting because isolation is a standard containment tactic for actively exploited, unpatchable systems, and it would be correct if the vulnerability were being exploited in real time and no compensating controls existed.

  • ✗

    Disable the application until a patch becomes available

    Why it's wrong here

    Disabling a business-critical legacy application causes an immediate operational outage, violating availability requirements. Furthermore, because the vendor has designated the application as legacy, a formal patch may never be released, making this an indefinite and unsustainable disruption to business continuity.

  • ✗

    Apply a virtual patch via an intrusion prevention system

    Why it's wrong here

    While deploying a virtual patch via an IPS is a highly effective technical action, it represents only a single, specific type of compensating control. The broader, more comprehensive next step is to formally document the risk and evaluate all potential compensating controls—such as host-based firewalls, WAFs, or segmentation—rather than prematurely limiting the remediation strategy to a network-level IPS signature.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.