CS0-003 Vulnerability Management Practice Question
During a vulnerability assessment, a security analyst discovers a critical vulnerability affecting a legacy application that cannot be patched due to vendor end-of-life status. Which of the following is the BEST next step?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Document the risk and implement compensating controls
When a patch is not available, implementing compensating controls is the best approach to mitigate risk. This may include network segmentation, access controls, or additional monitoring.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Document the risk and implement compensating controls
Why this is correct
When a legacy application cannot be patched, the vulnerability management lifecycle dictates that the risk must be formally accepted and documented in the risk register. To mitigate the exposure while maintaining business operations, the organization must implement compensating controls, such as network segmentation or strict access control lists, to reduce the likelihood or impact of exploitation.
- ✗
Remove the legacy application from the network immediately
Why it's wrong here
Removing the legacy application immediately would cause an operational outage, violating the requirement to maintain business continuity while the vulnerability is addressed. This action is tempting because isolation is a standard containment tactic for actively exploited, unpatchable systems, and it would be correct if the vulnerability were being exploited in real time and no compensating controls existed.
- ✗
Disable the application until a patch becomes available
Why it's wrong here
Disabling a business-critical legacy application causes an immediate operational outage, violating availability requirements. Furthermore, because the vendor has designated the application as legacy, a formal patch may never be released, making this an indefinite and unsustainable disruption to business continuity.
- ✗
Apply a virtual patch via an intrusion prevention system
Why it's wrong here
While deploying a virtual patch via an IPS is a highly effective technical action, it represents only a single, specific type of compensating control. The broader, more comprehensive next step is to formally document the risk and evaluate all potential compensating controls—such as host-based firewalls, WAFs, or segmentation—rather than prematurely limiting the remediation strategy to a network-level IPS signature.
Go deeper
Related to this question
Learn chapter
Patch and Remediation Workflows
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
End-of-life
End-of-life means a product or service is no longer being sold, updated, or supported by the manufacturer, and users should plan to upgrade or replace it.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.