Courseiva
mediumMultiple Choice

CS0-003 Practice Question: During a vulnerability assessment, a security…

During a vulnerability assessment, a security analyst discovers that a network device is running an outdated firmware version with known exploits. The device is critical to production and cannot be rebooted during business hours. Which of the following is the BEST approach to remediate this vulnerability?

⚠ Common exam trap

CompTIA often tests the distinction between remediation (removing the vulnerability) and mitigation (reducing risk without removal), leading candidates to mistakenly choose a compensating control like virtual patching instead of scheduling a proper firmware upgrade.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

✓

Schedule the firmware upgrade during the next maintenance window

Scheduling the firmware upgrade during the next maintenance window aligns with change management best practices for critical production devices that cannot tolerate downtime during business hours. This approach ensures the vulnerability is remediated in a controlled manner, minimizing operational risk while still addressing the known exploit.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • ✓

    Schedule the firmware upgrade during the next maintenance window

    Why this is correct

    Scheduling the firmware upgrade during an established maintenance window is the best practice because it balances security remediation with operational continuity. Firmware updates modify low-level hardware instructions and almost always require a system reboot, which causes temporary downtime. Planning this during a scheduled window minimizes business disruption while ensuring the vulnerability is permanently resolved.

  • ✗

    Apply the firmware patch immediately without rebooting

    Why it's wrong here

    Attempting to apply a firmware patch immediately without rebooting is technically unfeasible because firmware resides in non-volatile memory and requires a system initialization cycle to load the new code. Furthermore, applying patches immediately to production systems without testing or scheduled downtime violates change management protocols and risks causing unplanned outages.

  • ✗

    Implement a virtual patch via the IDS/IPS until a full patch is possible

    Why it's wrong here

    While implementing a virtual patch via an intrusion detection or prevention system (IDS/IPS) can mitigate risk, it is a temporary compensating control rather than a true remediation. Virtual patching only inspects network traffic for known exploit signatures and does not fix the underlying vulnerability in the firmware itself, leaving the system exposed to alternative attack vectors or local exploits.

  • ✗

    Request a hotfix from the vendor that does not require a reboot

    Why it's wrong here

    Requesting a rebootless hotfix from a vendor is impractical because custom hotfixes are rarely available on demand and still typically require a system restart to apply low-level code changes. Relying on this approach introduces unnecessary administrative delays and leaves the system vulnerable while waiting for a custom software package that may never be delivered.

About these practice questions

Courseiva writes every CS0-004 question from scratch — 701 in total, each with an explanation and a wrong-answer breakdown. None are copied from real exams or dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.