CS0-003 Security Operations Practice Question
During a vulnerability scan of internal hosts, a security analyst finds a critical vulnerability with a CVSS score of 9.8. The affected system is a legacy application that cannot be patched immediately. What should the analyst do next?
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Apply compensating controls and document the risk
The analyst should document the finding and apply compensating controls, such as network segmentation or firewall rules, to mitigate risk until a patch can be applied.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✗
Increase scan frequency to monitor the vulnerability
Why it's wrong here
Increasing the frequency of vulnerability scans only provides more frequent visibility into the presence of the flaw; it does not actively reduce the likelihood or impact of exploitation. Continuous monitoring is valuable for situational awareness, but it fails to implement any active defense or mitigation to protect the vulnerable host from potential threats.
- ✗
Mark the vulnerability as a false positive
Why it's wrong here
Marking a legitimate vulnerability as a false positive is a dangerous practice that artificially inflates the security posture by hiding real risks from reporting dashboards. This action should only be taken when rigorous manual verification proves that the vulnerability scanner's detection was incorrect and that the system is not actually susceptible to the identified flaw.
- ✗
Immediately shut down the system
Why it's wrong here
Shutting down an internal host immediately without assessing its criticality violates the principle of maintaining business continuity and can cause severe operational disruption. This drastic measure should be reserved for active, high-severity security incidents where containment is necessary, rather than as a standard response to a newly discovered static vulnerability.
- ✓
Apply compensating controls and document the risk
Why this is correct
When a permanent patch cannot be immediately deployed, implementing compensating controls—such as restricting network access via firewall rules or enabling specific intrusion prevention signatures—actively reduces the risk of exploitation. Documenting this risk and the associated temporary mitigations ensures compliance, maintains operational visibility, and establishes a clear path toward eventual remediation.
Go deeper
Related to this question
Learn chapter
OWASP Top 10 for Security Analysts
Key term
Firewall
A firewall is a network security system that monitors and controls incoming and outgoing traffic based on predetermined security rules to protect trusted internal networks from untrusted external networks.
Key term
Vulnerability
A vulnerability is a weakness in a system, network, or software that could be exploited by a threat to cause harm or unauthorized access.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.