mediumMultiple Select
CS0-003 Practice Question: Which items belong in a vulnerability exception…
Which items belong in a vulnerability exception request? (Choose three.)
⚠ Common exam trap
The CS0-004 exam often tests the distinction between operational risk acceptance (exception request) and asset lifecycle management (decommissioning), leading candidates to incorrectly include asset removal as part of the exception process.
Answer choices
Why each option matters
Answer the question above first, then reveal the full breakdown to understand why each option is right or wrong.
Correct answer & explanation
✓
Business justification for delayed remediation
A vulnerability exception request is a formal process to accept the risk of not remediating a vulnerability within the standard timeframe. A business justification for delayed remediation is a core component because it documents the operational, financial, or technical reasons why the fix cannot be applied immediately, which is required for risk acceptance by management. Without this justification, the exception lacks the necessary context for approval and audit compliance.
Answer analysis
Option-by-option breakdown
For each option: why learners choose it and why it is or isn't the right answer here.
- ✓
Business justification for delayed remediation
Why this is correct
A robust business justification is paramount for a vulnerability exception request, detailing why immediate remediation is impractical or detrimental to critical business operations. This justification must clearly articulate the operational impact, financial cost, or technical incompatibility that prevents standard vulnerability resolution. It serves as the foundation for management's informed decision to temporarily accept the associated risk, demonstrating due diligence in risk management.
- ✗
A request to remove the asset from inventory
Why it's wrong here
Requesting to remove an asset from inventory is an inappropriate action within a vulnerability exception request, as it merely obscures the asset and its associated risks rather than addressing them. Such a practice undermines asset management and visibility, creating 'shadow IT' that remains vulnerable but untracked, significantly increasing the organization's overall attack surface. A legitimate exception acknowledges the vulnerability and its host, focusing on risk mitigation rather than concealment.
- ✓
Expiration or review date
Why this is correct
An essential component of any vulnerability exception is a clearly defined expiration or mandatory review date, preventing the indefinite acceptance of known risks. This time limit ensures that the exception is not permanent and forces periodic re-evaluation of the vulnerability's status, the effectiveness of compensating controls, and the continued validity of the original business justification. Regular reviews promote continuous security improvement and prevent the accumulation of unaddressed technical debt.
- ✓
Compensating controls
Why this is correct
Compensating controls are critical elements of a vulnerability exception request, designed to reduce the risk posed by an unpatched vulnerability to an acceptable level. These alternative security measures, such as network segmentation, enhanced monitoring, or stricter access controls, do not eliminate the vulnerability itself but mitigate its exploitability or potential impact. Documenting these controls demonstrates a proactive approach to risk management while awaiting full remediation.
Go deeper
Related to this question
Learn chapter
Remediation SLAs and Risk Acceptance
Key term
Compliance
Compliance is the process of ensuring that an organization follows laws, regulations, standards, and internal policies that apply to its operations and data handling.
Key term
Risk acceptance
Risk acceptance is a risk management strategy where an organization acknowledges a potential risk but decides to tolerate it without taking active measures to reduce or eliminate it.
About these practice questions
This CS0-004 question is part of Courseiva's 701-question bank — original exam-style content with full explanations and wrong-answer analysis, never real exam questions or exam dumps. Learn why practice questions differ from exam dumps →
JA
Written by Johnson Ajibi, MSc IT Security
Senior Network & Security Engineer · founder of Courseiva
This CS0-004 practice question is part of Courseiva's free CompTIA certification practice question bank. Courseiva provides original exam-style practice questions with explanations, topic-based practice, mock exams, readiness tracking, and study analytics to help learners prepare for the CS0-004 exam.