Courseiva
mediumMultiple ChoiceObjective-mapped

CS0-003 Practice Question: During a vulnerability scan, an analyst discovers…

During a vulnerability scan, an analyst discovers a high-severity vulnerability on a critical database server. The server is in production and cannot be taken offline. The vendor has released a patch but requires a reboot. Which of the following should the analyst recommend FIRST?

⚠ Common exam trap

CompTIA often tests the candidate's ability to prioritize business continuity over immediate remediation, leading candidates to incorrectly choose 'Apply the patch immediately' (Option C) because they focus solely on the high severity without considering the operational impact of a reboot on a critical production server.

Answer choices

Why each option matters

Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.

Correct answer & explanation

Schedule the patch during the next maintenance window.

The database server is in production and cannot be taken offline, so the patch must be applied during a scheduled maintenance window to minimize business disruption. The vulnerability is high-severity, but the vendor requires a reboot, which would cause downtime; therefore, the first step is to plan the patch application at the next available maintenance window, not to apply it immediately or implement a workaround that may not fully mitigate the risk.

Answer analysis

Option-by-option breakdown

For each option: why learners choose it and why it is or isn't the right answer here.

  • Implement a workaround from the vendor.

    Why it's wrong here

    Implementing a workaround from the vendor, while offering temporary relief, is not the optimal first response for a high-severity vulnerability when a definitive patch is available. Workarounds often introduce additional operational complexity, may not fully mitigate the underlying risk, and still require the eventual application of the permanent fix. This approach is typically reserved for situations where a patch is not yet released or cannot be applied within a reasonable timeframe, rather than as a primary remediation step.

  • Schedule the patch during the next maintenance window.

    Why this is correct

    Scheduling the patch during the next maintenance window represents the best practice for addressing high-severity vulnerabilities in production environments. This approach allows for proper change management, including testing the patch in a non-production environment, planning for potential rollbacks, and communicating downtime to stakeholders. It effectively balances the need for security remediation with the critical requirement for system availability and operational stability, minimizing unplanned service disruptions.

  • Apply the patch immediately.

    Why it's wrong here

    Applying the patch immediately, without proper planning or adherence to change management protocols, carries significant risks that can outweigh the benefits of rapid remediation. Unscheduled patching bypasses crucial steps like impact analysis, compatibility testing, and stakeholder notification, potentially leading to unforeseen system instability, application failures, or unplanned downtime. Such impulsive actions can introduce new vulnerabilities or operational issues, making the situation worse than waiting for a controlled deployment.

  • Migrate the database to a new server.

    Why it's wrong here

    Migrating the database to a new server is an extreme and disproportionate response to a discovered high-severity vulnerability that can likely be addressed with a patch. Database migration is a complex, resource-intensive project requiring extensive planning, testing, and significant downtime, typically reserved for hardware end-of-life, major architectural changes, or unpatchable critical vulnerabilities. It is not a standard or efficient first step for remediating a patchable security flaw identified during a routine scan.

About these practice questions

This CS0-004 question is part of Courseiva's 236-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →

How Courseiva writes practice questions · Editorial policy

JA

Written by Johnson Ajibi, MSc IT Security

Senior Network & Security Engineer · founder of Courseiva

This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.