mediumMultiple Choice
CS0-003 Practice Question: During a vulnerability assessment, a security…
During a vulnerability assessment, a security analyst discovers that a network device is running an outdated firmware version with known exploits. The device is critical to production and cannot be rebooted during business hours. Which of the following is the BEST approach to remediate this vulnerability?
⚠ Common exam trap
CompTIA often tests the distinction between remediation (removing the vulnerability) and mitigation (reducing risk without removal), leading candidates to mistakenly choose a compensating control like virtual patching instead of scheduling a proper firmware upgrade.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Schedule the firmware upgrade during the next maintenance window
Scheduling the firmware upgrade during the next maintenance window aligns with change management best practices for critical production devices that cannot tolerate downtime during business hours. This approach ensures the vulnerability is remediated in a controlled manner, minimizing operational risk while still addressing the known exploit.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Schedule the firmware upgrade during the next maintenance window
Why this is correct
Scheduling the firmware upgrade during an established maintenance window is the best practice because it balances security remediation with operational continuity. Firmware updates modify low-level hardware instructions and almost always require a system reboot, which causes temporary downtime. Planning this during a scheduled window minimizes business disruption while ensuring the vulnerability is permanently resolved.
- ✗
Apply the firmware patch immediately without rebooting
Why it's wrong here
Attempting to apply a firmware patch immediately without rebooting is technically unfeasible because firmware resides in non-volatile memory and requires a system initialization cycle to load the new code. Furthermore, applying patches immediately to production systems without testing or scheduled downtime violates change management protocols and risks causing unplanned outages.
- ✗
Implement a virtual patch via the IDS/IPS until a full patch is possible
Why it's wrong here
While implementing a virtual patch via an intrusion detection or prevention system (IDS/IPS) can mitigate risk, it is a temporary compensating control rather than a true remediation. Virtual patching only inspects network traffic for known exploit signatures and does not fix the underlying vulnerability in the firmware itself, leaving the system exposed to alternative attack vectors or local exploits.
- ✗
Request a hotfix from the vendor that does not require a reboot
Why it's wrong here
Requesting a rebootless hotfix from a vendor is impractical because custom hotfixes are rarely available on demand and still typically require a system restart to apply low-level code changes. Relying on this approach introduces unnecessary administrative delays and leaves the system vulnerable while waiting for a custom software package that may never be delivered.
Go deeper
Related to this question
Learn chapter
Container and Kubernetes Security Analysis
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
Key term
Risk
Risk is the possibility that an event or action will negatively affect an organization's ability to achieve its goals, often measured in terms of likelihood and impact.
About these practice questions
Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.